CVE Feed

    Dashboard / CVE / CVE-2023-0750

    CVE-2023-0750

    Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface.  When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to : - Change the password, resulting in a DOS of the users - Change the streaming source, compromising the integrity of the stream - Change the streaming destination, compromising the confidentiality of the stream This issue affects Yellowbrik: PEC 1864. No patch has been issued by the manufacturer as this model was discontinued.

    Published:Apr 6, 2023
    Last Modified:Feb 10, 2025
    EPS:Apr 6, 2023
    EPSS Score:0.00055
    CVSS Score:9.8

    Affected Products

    Vendor
    Lynx-technik
    Product
    Yellobrik Pec 1864
    Vendor
    Lynx-technik
    Product
    Yellobrik Pec 1864 Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High