ID

VAR-202102-1595


TITLE

China Telecom Tianyi store camera has weak password vulnerability

Trust: 0.6

sources: CNVD: CNVD-2021-01301

DESCRIPTION

Tianyi Kandian is a security service that integrates cameras, video, real-time monitoring, pan-tilt control, alarm, and storage, launched by China Power Hongxin Information Technology Co., Ltd., for companies, shops and other places that require visual management. Terminal management software and Internet service platform use computers and smart phones as media to realize remote control and help users better perform security and visual management. A weak password vulnerability exists in the cameras of China Telecom Tianyi Store. Attackers can use the vulnerability to obtain sensitive information.

Trust: 0.6

sources: CNVD: CNVD-2021-01301

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-01301

AFFECTED PRODUCTS

vendor:clp hongxin informationmodel:china telecom tianyi store camerascope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2021-01301

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-01301
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2021-01301
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-01301

EXTERNAL IDS

db:CNVDid:CNVD-2021-01301

Trust: 0.6

sources: CNVD: CNVD-2021-01301

SOURCES

db:CNVDid:CNVD-2021-01301

LAST UPDATE DATE

2022-05-04T10:10:38.937000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-01301date:2021-01-08T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-01301date:2021-02-12T00:00:00