Description
A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows an attacker to view the private data of all users of the Guardzilla device.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
There is no vendor-provided fix available, see work_around.
Vendor Workaround
Users concerned with video privacy should disable the cloud storage functionality provided by the vendor.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-17329 | A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security System allows an attacker to view the private data of all users of the Guardzilla device. |
References
History
No history.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-09-16T21:04:09.840Z
Reserved: 2018-01-12T00:00:00.000Z
Link: CVE-2018-5560
No data.
Status : Modified
Published: 2019-01-31T21:29:00.270
Modified: 2024-11-21T04:09:03.990
Link: CVE-2018-5560
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD