CVE-2023-3104

Lack of authentication vulnerability. An unauthenticated local user is able to see through the cameras using the web server due to the lack of any form of authentication.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:unitree:a1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:unitree:a1:1.16:*:*:*:*:*:*:*

History

21 Nov 2024, 08:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.7
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-unitree-robotics-a1 - Vendor Advisory () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-unitree-robotics-a1 - Vendor Advisory

30 Nov 2023, 01:50

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Unitree
Unitree a1
Unitree a1 Firmware
CWE CWE-306
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-unitree-robotics-a1 - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-unitree-robotics-a1 - Vendor Advisory
CPE cpe:2.3:o:unitree:a1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:unitree:a1:1.16:*:*:*:*:*:*:*

22 Nov 2023, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-22 12:15

Updated : 2024-11-21 08:16


NVD link : CVE-2023-3104

Mitre link : CVE-2023-3104

CVE.ORG link : CVE-2023-3104


JSON object : View

Products Affected

unitree

  • a1
  • a1_firmware
CWE
CWE-306

Missing Authentication for Critical Function