CVE-2019-13953

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/09/2019
Last modified:
24/08/2020

Description

An exploitable authentication bypass vulnerability exists in the Bluetooth Low Energy (BLE) authentication module of YI M1 Mirrorless Camera V3.2-cn. An attacker can send a set of BLE commands to trigger this vulnerability, resulting in sensitive data leakage (e.g., personal photos). An attacker can also control the camera to record or take a picture after bypassing authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:xiaoyi:yi_m1_mirrorless_camera_firmware:3.2-cn:*:*:*:*:*:*:*
cpe:2.3:h:xiaoyi:yi_m1_mirrorless_camera:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools