ID

VAR-201705-3694


CVE

CVE-2017-8403


TITLE

360fly 4K Access control vulnerabilities in cameras

Trust: 0.8

sources: JVNDB: JVNDB-2017-003865

DESCRIPTION

360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, which is available at any time and does not require a password. This affects firmware 2.1.4. Exploitation can use the 360fly Android or iOS application, or the BlueZ gatttool program. 360fly 4K The camera contains an access control vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. 360Fly is a famous camera manufacturer. 360fly 4K is a 360-degree camera capable of recording 4k images. There is a security vulnerability in the 360fly 4K camera, which stems from the fact that the program does not set a password

Trust: 2.34

sources: NVD: CVE-2017-8403 // JVNDB: JVNDB-2017-003865 // CNVD: CNVD-2017-06999 // VULHUB: VHN-116606 // VULMON: CVE-2017-8403

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

category:['camera device']sub_category:camera

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2017-06999

AFFECTED PRODUCTS

vendor:360flymodel:4k camerascope:eqversion:2.1.4

Trust: 1.6

vendor:360flymodel:4kscope:eqversion:2.1.4

Trust: 0.8

vendor:360flymodel:4k camerasscope:eqversion:2.1.4.

Trust: 0.6

sources: CNVD: CNVD-2017-06999 // JVNDB: JVNDB-2017-003865 // CNNVD: CNNVD-201705-021 // NVD: CVE-2017-8403

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-8403
value: HIGH

Trust: 1.0

NVD: CVE-2017-8403
value: HIGH

Trust: 0.8

CNVD: CNVD-2017-06999
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201705-021
value: HIGH

Trust: 0.6

VULHUB: VHN-116606
value: HIGH

Trust: 0.1

VULMON: CVE-2017-8403
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-8403
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2017-06999
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-116606
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-8403
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-06999 // VULHUB: VHN-116606 // VULMON: CVE-2017-8403 // JVNDB: JVNDB-2017-003865 // CNNVD: CNNVD-201705-021 // NVD: CVE-2017-8403

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

problemtype:CWE-284

Trust: 0.9

sources: VULHUB: VHN-116606 // JVNDB: JVNDB-2017-003865 // NVD: CVE-2017-8403

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-201705-021

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201705-021

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-003865

PATCH

title:トップページurl:http://shop360fly.jp/

Trust: 0.8

title:360fly4K identity bypass vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/93954

Trust: 0.6

sources: CNVD: CNVD-2017-06999 // JVNDB: JVNDB-2017-003865

EXTERNAL IDS

db:NVDid:CVE-2017-8403

Trust: 3.3

db:JVNDBid:JVNDB-2017-003865

Trust: 0.8

db:CNNVDid:CNNVD-201705-021

Trust: 0.7

db:CNVDid:CNVD-2017-06999

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULHUBid:VHN-116606

Trust: 0.1

db:VULMONid:CVE-2017-8403

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2017-06999 // VULHUB: VHN-116606 // VULMON: CVE-2017-8403 // JVNDB: JVNDB-2017-003865 // CNNVD: CNNVD-201705-021 // NVD: CVE-2017-8403

REFERENCES

url:https://www.slideshare.net/fuguet/bluediot-when-a-mature-and-immature-technology-mixes-becomes-an-idiot-situation-75529672

Trust: 3.2

url:https://nvd.nist.gov/vuln/detail/cve-2017-8403

Trust: 1.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-8403

Trust: 0.8

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/287.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2017-06999 // VULHUB: VHN-116606 // VULMON: CVE-2017-8403 // JVNDB: JVNDB-2017-003865 // CNNVD: CNNVD-201705-021 // NVD: CVE-2017-8403

SOURCES

db:OTHERid: -
db:CNVDid:CNVD-2017-06999
db:VULHUBid:VHN-116606
db:VULMONid:CVE-2017-8403
db:JVNDBid:JVNDB-2017-003865
db:CNNVDid:CNNVD-201705-021
db:NVDid:CVE-2017-8403

LAST UPDATE DATE

2025-04-20T22:01:44.095000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-06999date:2017-05-19T00:00:00
db:VULHUBid:VHN-116606date:2019-10-03T00:00:00
db:VULMONid:CVE-2017-8403date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2017-003865date:2017-06-09T00:00:00
db:CNNVDid:CNNVD-201705-021date:2019-10-23T00:00:00
db:NVDid:CVE-2017-8403date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-06999date:2017-05-19T00:00:00
db:VULHUBid:VHN-116606date:2017-05-01T00:00:00
db:VULMONid:CVE-2017-8403date:2017-05-01T00:00:00
db:JVNDBid:JVNDB-2017-003865date:2017-06-09T00:00:00
db:CNNVDid:CNNVD-201705-021date:2017-05-09T00:00:00
db:NVDid:CVE-2017-8403date:2017-05-01T20:59:00.170