CVE-2018-18602: Critical severity guardzilla 360 outdoor vulnerability
Published Dec 31, 2018
·Updated
The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.
Affected Software
24 affected components
Guardzilla 360 Outdoor Firmware
Guardzilla 360 Outdoor
Guardzilla 180 Outdoor Firmware
Guardzilla 180 Outdoor
Guardzilla 360 Indoor Firmware
Guardzilla 360 Indoor
Guardzilla 180 Indoor Firmware
Guardzilla 180 Indoor
Guardzilla Outdoor Hd Camera Firmware
Guardzilla Outdoor Hd Camera
Guardzilla Indoor Hd Camera Firmware
Guardzilla Indoor Hd Camera
All of the following
Guardzilla 360 Outdoor Firmware
Guardzilla 360 Outdoor
All of the following
Guardzilla 180 Outdoor Firmware
Guardzilla 180 Outdoor
All of the following
Guardzilla 360 Indoor Firmware
Guardzilla 360 Indoor
All of the following
Guardzilla 180 Indoor Firmware
Guardzilla 180 Indoor
All of the following
Guardzilla Outdoor Hd Camera Firmware
Guardzilla Outdoor Hd Camera
All of the following
Guardzilla Indoor Hd Camera Firmware
Guardzilla Indoor Hd Camera
Event History
Dec 31, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18602?
CVE-2018-18602 has a medium severity due to the potential for unauthorized camera access and monitoring.
2
How do I fix CVE-2018-18602?
To mitigate CVE-2018-18602, it is recommended to update the firmware of the affected Guardzilla smart cameras.
3
What exploit does CVE-2018-18602 enable?
CVE-2018-18602 enables user enumeration, which can lead to arbitrary access to camera feeds and monitoring.
4
Which devices are affected by CVE-2018-18602?
CVE-2018-18602 affects various Guardzilla smart cameras, including the 360 Outdoor and 180 Outdoor models.
5
Is CVE-2018-18602 a permanent vulnerability?
No, CVE-2018-18602 can be addressed by applying the appropriate firmware updates provided by Guardzilla.