CVE-2023-3104

Lack of authentication vulnerability. An unauthenticated local user is able to see through the cameras using the web server due to the lack of any form of authentication.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:unitree:a1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:unitree:a1:1.16:*:*:*:*:*:*:*

History

30 Nov 2023, 01:50

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-unitree-robotics-a1 - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-unitree-robotics-a1 - Vendor Advisory
CPE cpe:2.3:o:unitree:a1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:unitree:a1:1.16:*:*:*:*:*:*:*
First Time Unitree a1
Unitree
Unitree a1 Firmware
CWE CWE-306
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

22 Nov 2023, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-22 12:15

Updated : 2024-04-11 01:21


NVD link : CVE-2023-3104

Mitre link : CVE-2023-3104

CVE.ORG link : CVE-2023-3104


JSON object : View

Products Affected

unitree

  • a1_firmware
  • a1
CWE
CWE-306

Missing Authentication for Critical Function