CVE-2018-17917
10.10.2018, 15:29
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of the supported apps.Enginsight
Vendor | Product | Version |
---|---|---|
xiongmaitech | xmeye_p2p_cloud_server | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-341 - Predictable from Observable StateA number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.