CVE-2024-31798

Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:gncchome:gncc_c2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:gncchome:_gncc_c2:-:*:*:*:*:*:*:*

History

16 Aug 2024, 13:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.4
v2 : unknown
v3 : 6.8
References () https://gncchome.com/collections/indoor-camera/products/c2-indoor-security-camera-1080p - () https://gncchome.com/collections/indoor-camera/products/c2-indoor-security-camera-1080p - Product
References () https://www.nsideattacklogic.de/advisories/NSIDE-SA-2024-001 - () https://www.nsideattacklogic.de/advisories/NSIDE-SA-2024-001 - Exploit, Third Party Advisory
CWE CWE-798
First Time Gncchome Gncc C2
Gncchome gncc C2 Firmware
Gncchome
CPE cpe:2.3:o:gncchome:gncc_c2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:gncchome:_gncc_c2:-:*:*:*:*:*:*:*
Summary
  • (es) La contraseña root idéntica codificada para todos los dispositivos en GNCC's GC2 Indoor Security Camera 1080P permite a un atacante con acceso físico recuperar la contraseña de root para todos los dispositivos similares

15 Aug 2024, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.4
CWE CWE-259

15 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-15 17:15

Updated : 2024-08-16 13:59


NVD link : CVE-2024-31798

Mitre link : CVE-2024-31798

CVE.ORG link : CVE-2024-31798


JSON object : View

Products Affected

gncchome

  • gncc_c2_firmware
  • _gncc_c2
CWE
CWE-798

Use of Hard-coded Credentials

CWE-259

Use of Hard-coded Password