CVE-2024-4583

A vulnerability classified as problematic was found in Faraday GM8181 and GM828x up to 20240429. Affected by this vulnerability is an unknown functionality of the component Request Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier VDB-263305 was assigned to this vulnerability.
Configurations

No configuration.

History

21 Nov 2024, 09:43

Type Values Removed Values Added
References () https://file.notion.so/f/f/3f67e7ef-2ba8-446a-9721-f87d0baa1695/193e9734-f9eb-44b0-bd85-92263d0e84ec/get_password_submit.py?id=8fd5a7e0-bc2d-4ef8-9037-d3c1b68a6be1&table=block&spaceId=3f67e7ef-2ba8-446a-9721-f87d0baa1695&expirationTimestamp=1715148000000& - () https://file.notion.so/f/f/3f67e7ef-2ba8-446a-9721-f87d0baa1695/193e9734-f9eb-44b0-bd85-92263d0e84ec/get_password_submit.py?id=8fd5a7e0-bc2d-4ef8-9037-d3c1b68a6be1&table=block&spaceId=3f67e7ef-2ba8-446a-9721-f87d0baa1695&expirationTimestamp=1715148000000& -
References () https://netsecfish.notion.site/Unauthorized-Credential-Exposure-in-Faraday-Technology-Grain-Media-GM828x-GM8181-DVR-Devices-6a501c33e5d44beab7148074d2214b8f?pvs=4 - () https://netsecfish.notion.site/Unauthorized-Credential-Exposure-in-Faraday-Technology-Grain-Media-GM828x-GM8181-DVR-Devices-6a501c33e5d44beab7148074d2214b8f?pvs=4 -
References () https://vuldb.com/?ctiid.263305 - () https://vuldb.com/?ctiid.263305 -
References () https://vuldb.com/?id.263305 - () https://vuldb.com/?id.263305 -
References () https://vuldb.com/?submit.324403 - () https://vuldb.com/?submit.324403 -

14 May 2024, 15:44

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad clasificada como problemática fue encontrada en Faraday GM8181 y GM828x hasta 20240429. Una función desconocida del componente Request Handler es afectada por esta vulnerabilidad. La manipulación conduce a la divulgación de información. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. Se recomienda actualizar el componente afectado. A esta vulnerabilidad se le asignó el identificador VDB-263305.

07 May 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-07 11:15

Updated : 2024-11-21 09:43


NVD link : CVE-2024-4583

Mitre link : CVE-2024-4583

CVE.ORG link : CVE-2024-4583


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor