CVE-2021-24046
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device software before 2107460.6810.0.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2107460.6810.0 |
| Running on/with | Platform Versions |
|---|---|
Ray Ban Stories Rw4003 65582v 48 23 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2107460.6810.0 |
| Running on/with | Platform Versions |
|---|---|
Ray Ban Stories Rw4002 601/71 50 22 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2107460.6810.0 |
| Running on/with | Platform Versions |
|---|---|
Ray Ban Stories Rw4005 656013 51 20 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2107460.6810.0. |
| Running on/with | Platform Versions |
|---|---|
Ray Ban Stories Rw4005 6563m3 51 20 | All versions |
Related CWEs
CWE-425
Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
CWE-471
Modification of Assumed-Immutable Data (MAID)
The product does not properly protect an assumed-immutable element from being modified by an attacker.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.