CVE-2024-13893

HIGH

Smartwares cameras <3.3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, might share same credentials for telnet service. Hash of the password can be retrieved through physical access to SPI connected memory. For the telnet service to be enabled, the inserted SD card needs to have a folder with a specific name created.  Two products were tested, but since the vendor has not replied to reports, patching status remains unknown, as well as groups of devices and firmware ranges in which the same password is shared. Newer firmware versions might be vulnerable as well.

Scores

CVSS v4 7.5
EPSS 0.0005
EPSS Percentile 14.5%
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1392
Status published
Products (2)
Smartwares/C724IP < 3.3.0
Smartwares/CIP-37210AT < 3.3.0
Published Mar 06, 2025
Tracked Since Feb 18, 2026