CVE-2024-7205
sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary user
Severity Score
9.4
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.
When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.
*Credits:
Aarav Sinha, Senior Security Researcher, FEV India Pvt Ltd., Jerin Sunny, Security Researcher, FEV India Pvt Ltd., Shakir Zari,Security Researcher,FEV India Pvt Ltd.
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-07-29 CVE Reserved
- 2024-07-31 CVE Published
- 2024-07-31 CVE Updated
- 2024-07-31 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-201: Insertion of Sensitive Information Into Sent Data
CAPEC
- CAPEC-383: Harvesting Information via API Event Monitoring
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
CoolKit Search vendor "CoolKit" | EWeLink Cloud Service Search vendor "CoolKit" for product "EWeLink Cloud Service" | >= 2.0.0 < 2.19.0 Search vendor "CoolKit" for product "EWeLink Cloud Service" and version " >= 2.0.0 < 2.19.0" | en |
Affected
|