CVE-2015-8254 describes a critical integrity protection flaw in the Frontel protocol, specifically versions prior to 3, used in RSI Video Technologies Videofied devices. This vulnerability allows man-in-the-middle attackers to manipulate the client-server data stream, enabling them to either trigger false alarms or deactivate legitimate alarms. With a CVSS score of 5.9 (Medium) and a vector indicating network-based attacks with high complexity, the impact is primarily on integrity, with no confidentiality or availability impact noted. There is no evidence of active exploitation, nor are there publicly available exploit codes in Metasploit or ExploitDB, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0CPE matchmatch criteria | cpe:2.3:a:rsi_video_technologies:frontel_protocol:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.