CVE Feed

    Dashboard / CVE / CVE-2014-1901

    CVE-2014-1901

    Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware 4.30 and earlier, allow remote authenticated users to cause a denial of service (reboot) via a malformed (1) path parameter to en/store_main.asp, (2) item parameter to en/account/accedit.asp, or (3) emailid parameter to en/smtpclient.asp. NOTE: this issue can be exploited without authentication by leveraging CVE-2014-1900.

    Published:May 14, 2015
    Last Modified:Apr 12, 2025
    EPS:May 14, 2015
    EPSS Score:0.00623
    CVSS Score:6.8

    Affected Products

    Vendor
    Y-cam
    Product
    Ycb001
    Vendor
    Y-cam
    Product
    Ycb001 Firmware
    Vendor
    Y-cam
    Product
    Ycb002
    Vendor
    Y-cam
    Product
    Ycb002 Firmware
    Vendor
    Y-cam
    Product
    Ycb003
    Vendor
    Y-cam
    Product
    Ycb003 Firmware
    Vendor
    Y-cam
    Product
    Ycb004
    Vendor
    Y-cam
    Product
    Ycb004 Firmware
    Vendor
    Y-cam
    Product
    Ycbl03
    Vendor
    Y-cam
    Product
    Ycbl03 Firmware
    Vendor
    Y-cam
    Product
    Ycblb3
    Vendor
    Y-cam
    Product
    Ycblb3 Firmware
    Vendor
    Y-cam
    Product
    Ycblhd5
    Vendor
    Y-cam
    Product
    Ycblhd5 Firmware
    Vendor
    Y-cam
    Product
    Yceb03
    Vendor
    Y-cam
    Product
    Yceb03 Firmware
    Vendor
    Y-cam
    Product
    Yck002
    Vendor
    Y-cam
    Product
    Yck002 Firmware
    Vendor
    Y-cam
    Product
    Yck003
    Vendor
    Y-cam
    Product
    Yck003 Firmware
    Vendor
    Y-cam
    Product
    Yck004
    Vendor
    Y-cam
    Product
    Yck004 Firmware
    Vendor
    Y-cam
    Product
    Ycw001
    Vendor
    Y-cam
    Product
    Ycw001 Firmware
    Vendor
    Y-cam
    Product
    Ycw002
    Vendor
    Y-cam
    Product
    Ycw002 Firmware
    Vendor
    Y-cam
    Product
    Ycw003
    Vendor
    Y-cam
    Product
    Ycw003 Firmware
    Vendor
    Y-cam
    Product
    Ycw004
    Vendor
    Y-cam
    Product
    Ycw004 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High