CVE-2024-47789

HIGH

D3D Security IP Camera D8801 - Info Disclosure

Title source: llm
STIX 2.1

Description

** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentication scheme of the HTTP header protocol where authorization tag contain a Base-64 encoded username and password. A remote attacker could exploit this vulnerability by crafting a HTTP packet leading to exposure of user credentials of the targeted device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Scores

CVSS v4 8.7
EPSS 0.0035
EPSS Percentile 57.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-319
Status published
Products (1)
D3D Security/IP Camera D8801 All versions
Published Oct 04, 2024
Tracked Since Feb 18, 2026