An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
History

Tue, 03 Dec 2024 21:15:00 +0000


Tue, 03 Dec 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Lorextechnology
Lorextechnology w461asc-e Firmware
CPEs cpe:2.3:o:lorextechnology:w461asc-e_firmware:-:*:*:*:*:*:*:*
Vendors & Products Lorextechnology
Lorextechnology w461asc-e Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Dec 2024 17:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
Title Lorex 2K Indoor Wi-Fi Security Camera - Out of bounds heap read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published: 2024-12-03T17:20:45.858Z

Updated: 2024-12-03T21:02:16.869Z

Reserved: 2024-11-12T13:42:42.323Z

Link: CVE-2024-52545

cve-icon Vulnrichment

Updated: 2024-12-03T18:38:53.243Z

cve-icon NVD

Status : Received

Published: 2024-12-03T18:15:15.543

Modified: 2024-12-03T21:15:07.490

Link: CVE-2024-52545

cve-icon Redhat

No data.