René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

123 lines
3.5 KiB
JSON

{
"id": "CVE-2015-4400",
"sourceIdentifier": "cve@mitre.org",
"published": "2018-02-06T16:29:00.527",
"lastModified": "2018-03-13T19:13:47.697",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Ring (formerly DoorBot) video doorbells allow remote attackers to obtain sensitive information about the wireless network configuration by pressing the set up button and leveraging an API in the GainSpan Wi-Fi module."
},
{
"lang": "es",
"value": "Los videoporteros Ring (anteriormente DoorBot) permiten que atacantes remotos obtengan informaci\u00f3n sensible sobre la configuraci\u00f3n de red inal\u00e1mbrica presionando el bot\u00f3n de configuraci\u00f3n y utilizando una API en el m\u00f3dulo Wi-Fi GainSpan."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "PHYSICAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.6,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 2.1
},
"baseSeverity": "LOW",
"exploitabilityScore": 3.9,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:ring:ring_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "C06754C9-7ACD-4E01-AB6B-968168235C25"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:ring:ring:-:*:*:*:*:*:*:*",
"matchCriteriaId": "DED03787-44C4-436A-95F3-FA562BD28F5A"
}
]
}
]
}
],
"references": [
{
"url": "https://fortiguard.com/zeroday/FG-VD-15-021",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://www.pentestpartners.com/security-blog/steal-your-wi-fi-key-from-your-doorbell-iot-wtf/",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
}
]
}