CVE-2024-48770

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 922

Summary

CVE-2024-48770 is a newly disclosed vulnerability affecting Plug n Play Camera's com.wisdomcity.zwave software version 1.1.0. This issue permits remote attackers to access sensitive data during the firmware update process, posing a significant risk to security and privacy. The vulnerability can be exploited without requiring authentication or physical access, making it an elevated threat. The exact nature of the information obtainable through this exploit is not yet clear, but it is advised that users upgrade to the latest software version as soon as it becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share