CVE-2023-43271 describes an incorrect access control vulnerability in 70mai a500s v1.2.119 firmware, allowing unauthorized access and deletion of driving recorder video files via FTP and other protocols. This critical vulnerability, with a CVSS score of 9.1, presents a high risk due to its network-based attack vector, low complexity, and significant impact on confidentiality and integrity. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for data loss makes this a serious concern for affected devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.119CPE matchmatch criteria | cpe:2.3:o:70mai:a500s_firmware:1.2.119:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.