Record summary

CVE-2021-3577 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE Listvariousaffected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHMotorola Baby Monitors - Remote Command ExecutionCVSS 8.8

Motorola Baby Monitors contains multiple interface vulnerabilities could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected device, potentially leading to unauthorized access, data theft, or further compromise of the network.

Remediation

Apply the latest firmware update provided by Motorola to mitigate the vulnerability and ensure the device is not accessible from untrusted networks.

WeaknessesCWE-863CWE-78
Authorsgy741
Template tagscve2021cverceoastmotorolaiotbinatoneglobalvkevvuln
CVSS vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:binatoneglobal:halo\+_camera_firmware:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2