CVE-2021-24046

A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device software before 2107460.6810.0.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ray-ban:stories_rw4003_65582v_48-23_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ray-ban:stories_rw4003_65582v_48-23:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ray-ban:stories_rw4002_601\/71_50-22_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ray-ban:stories_rw4002_601\/71_50-22:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ray-ban:stories_rw4005_656013_51-20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ray-ban:stories_rw4005_656013_51-20:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ray-ban:stories_rw4005_6563m3_51-20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ray-ban:stories_rw4005_6563m3_51-20:-:*:*:*:*:*:*:*

History

21 Jan 2022, 20:07

Type Values Removed Values Added
CWE CWE-425
First Time Ray-ban stories Rw4005 656013 51-20
Ray-ban stories Rw4003 65582v 48-23
Ray-ban stories Rw4002 601\/71 50-22 Firmware
Ray-ban stories Rw4005 6563m3 51-20 Firmware
Ray-ban
Ray-ban stories Rw4005 656013 51-20 Firmware
Ray-ban stories Rw4002 601\/71 50-22
Ray-ban stories Rw4003 65582v 48-23 Firmware
Ray-ban stories Rw4005 6563m3 51-20
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3
CPE cpe:2.3:o:ray-ban:stories_rw4003_65582v_48-23_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ray-ban:stories_rw4002_601\/71_50-22:-:*:*:*:*:*:*:*
cpe:2.3:h:ray-ban:stories_rw4005_656013_51-20:-:*:*:*:*:*:*:*
cpe:2.3:o:ray-ban:stories_rw4005_6563m3_51-20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ray-ban:stories_rw4003_65582v_48-23:-:*:*:*:*:*:*:*
cpe:2.3:h:ray-ban:stories_rw4005_6563m3_51-20:-:*:*:*:*:*:*:*
cpe:2.3:o:ray-ban:stories_rw4005_656013_51-20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ray-ban:stories_rw4002_601\/71_50-22_firmware:*:*:*:*:*:*:*:*
References (CONFIRM) https://www.facebook.com/security/advisories/cve-2021-24046 - (CONFIRM) https://www.facebook.com/security/advisories/cve-2021-24046 - Vendor Advisory

14 Jan 2022, 18:24

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-14 18:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-24046

Mitre link : CVE-2021-24046

CVE.ORG link : CVE-2021-24046


JSON object : View

Products Affected

ray-ban

  • stories_rw4005_656013_51-20_firmware
  • stories_rw4002_601\/71_50-22
  • stories_rw4005_656013_51-20
  • stories_rw4003_65582v_48-23_firmware
  • stories_rw4005_6563m3_51-20
  • stories_rw4005_6563m3_51-20_firmware
  • stories_rw4002_601\/71_50-22_firmware
  • stories_rw4003_65582v_48-23
CWE
CWE-425

Direct Request ('Forced Browsing')

CWE-471

Modification of Assumed-Immutable Data (MAID)