CVE-2024-31798

Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:gncchome:gncc_c2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:gncchome:_gncc_c2:-:*:*:*:*:*:*:*

History

16 Aug 2024, 13:59

Type Values Removed Values Added
CPE cpe:2.3:o:gncchome:gncc_c2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:gncchome:_gncc_c2:-:*:*:*:*:*:*:*
CWE CWE-798
Summary
  • (es) La contraseña root idéntica codificada para todos los dispositivos en GNCC's GC2 Indoor Security Camera 1080P permite a un atacante con acceso físico recuperar la contraseña de root para todos los dispositivos similares
First Time Gncchome gncc C2 Firmware
Gncchome Gncc C2
Gncchome
CVSS v2 : unknown
v3 : 6.4
v2 : unknown
v3 : 6.8
References () https://gncchome.com/collections/indoor-camera/products/c2-indoor-security-camera-1080p - () https://gncchome.com/collections/indoor-camera/products/c2-indoor-security-camera-1080p - Product
References () https://www.nsideattacklogic.de/advisories/NSIDE-SA-2024-001 - () https://www.nsideattacklogic.de/advisories/NSIDE-SA-2024-001 - Exploit, Third Party Advisory

15 Aug 2024, 18:35

Type Values Removed Values Added
CWE CWE-259
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.4

15 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-15 17:15

Updated : 2024-08-16 13:59


NVD link : CVE-2024-31798

Mitre link : CVE-2024-31798

CVE.ORG link : CVE-2024-31798


JSON object : View

Products Affected

gncchome

  • _gncc_c2
  • gncc_c2_firmware
CWE
CWE-798

Use of Hard-coded Credentials

CWE-259

Use of Hard-coded Password