CVE-2023-47353

HIGH

Imoulife Imou GO - Download Without Integrity Check

Title source: rule
STIX 2.1

Description

An issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitrary files.

Scores

CVSS v3 8.8
EPSS 0.0017
EPSS Percentile 38.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-494
Status published
Products (1)
imoulife/imou_go 1.0.11
Published Feb 06, 2024
Tracked Since Feb 18, 2026