The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.
                
            References
                    | Link | Resource | 
|---|---|
| https://labs.bitdefender.com/2018/12/iot-report-major-flaws-in-guardzilla-cameras-allow-remote-hijack-of-the-security-device/ | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
Configuration 2 (hide)
| AND | 
            
            
 
  | 
    
Configuration 3 (hide)
| AND | 
            
            
 
  | 
    
Configuration 4 (hide)
| AND | 
            
            
 
  | 
    
Configuration 5 (hide)
| AND | 
            
            
 
  | 
    
Configuration 6 (hide)
| AND | 
            
            
 
  | 
    
History
                    No history.
Information
                Published : 2018-12-31 16:29
Updated : 2020-08-24 17:37
NVD link : CVE-2018-18602
Mitre link : CVE-2018-18602
CVE.ORG link : CVE-2018-18602
JSON object : View
Products Affected
                guardzilla
- 180_outdoor_firmware
 - 180_indoor
 - 180_indoor_firmware
 - 360_outdoor_firmware
 - 360_outdoor
 - outdoor_hd_camera
 - 360_indoor_firmware
 - outdoor_hd_camera_firmware
 - indoor_hd_camera_firmware
 - indoor_hd_camera
 - 180_outdoor
 - 360_indoor
 
CWE
                
                    
                        
                        CWE-330
                        
            Use of Insufficiently Random Values
