NVD
- Id
- 30437
- Name
- CVE-2014-1901
- Description
- Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware 4.30 and earlier, allow remote authenticated users to cause a denial of service (reboot) via a malformed (1) path parameter to en/store_main.asp, (2) item parameter to en/account/accedit.asp, or (3) emailid parameter to en/smtpclient.asp. NOTE: this issue can be exploited without authentication by leveraging CVE-2014-1900.
- Reject
- CVSS Version
- 2
- CVSS Score
- 6.8
- Severity
- Medium
- CVSS Base Score
- 6.8
- CVSS Impact Subscore
- 6.9
- CVSS Exploit Subscore
- 8
- CVSS Vector
- (AV:N/AC:L/Au:S/C:N/I:N/A:C)
- Pub Date
- 2017-01-19
- Published
- 2015-05-13
- Modified Date
- 2015-05-15
- Seq
- 2014-1901