CVE-2019-20461
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 295
Summary
CVE-2019-20461: A vulnerability was discovered in the Alecto IVM-100 2019 devices, which use a custom UDP protocol for video and audio services. Though no password or username is transmitted over this protocol, an attacker can establish unauthorized sessions by using only the encoded device UID. Since authentication occurs at the client side, it's possible for an attacker to connect to these devices over the internet. This weakness may lead to unauthorized access and potential security threats.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.