cve/2017/CVE-2017-16867.md

19 lines
919 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2017-16867](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16867)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Amazon Key through 2017-11-16 mishandles Cloud Cam 802.11 deauthentication frames during the delivery process, which makes it easier for (1) delivery drivers to freeze a camera and re-enter a house for unfilmed activities or (2) attackers to freeze a camera and enter a house if a delivery driver failed to ensure a locked door before leaving.
### POC
#### Reference
- https://www.theverge.com/2017/11/16/16665064/amazon-key-camera-disable
- https://www.wired.com/story/amazon-key-flaw-let-deliverymen-disable-your-camera/
#### Github
No PoCs found on GitHub currently.