ID

VAR-201910-1859


TITLE

Baidu Tiangong Intelligent Platform Denial of Service Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2019-34661

DESCRIPTION

Baidu Tiangong Intelligent Platform is a cloud service platform for the Internet of Things field. It communicates through mainstream IoT protocols (such as MQTT), and can build IoT projects between smart devices and the cloud. There is a denial-of-service vulnerability in Baidu Tiangong's intelligent platform. Attackers can use their own identity credentials to construct others' ClientIDs to conduct denial-of-service attacks.

Trust: 0.6

sources: CNVD: CNVD-2019-34661

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-34661

AFFECTED PRODUCTS

vendor:baidu wangxunmodel:tiangong intelligent platformscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2019-34661

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-34661
value: HIGH

Trust: 0.6

CNVD: CNVD-2019-34661
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2019-34661

PATCH

title:Baidu Tiangong Intelligent Platform Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/180867

Trust: 0.6

sources: CNVD: CNVD-2019-34661

EXTERNAL IDS

db:CNVDid:CNVD-2019-34661

Trust: 0.6

sources: CNVD: CNVD-2019-34661

SOURCES

db:CNVDid:CNVD-2019-34661

LAST UPDATE DATE

2022-05-04T10:11:17.190000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-34661date:2019-10-12T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-34661date:2019-10-26T00:00:00