Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Xiaoyi Subscribe
Filtered by product Yi M1 Mirrorless Camera
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13953 1 Xiaoyi 2 Yi M1 Mirrorless Camera, Yi M1 Mirrorless Camera Firmware 2020-08-24 8.3 HIGH 8.8 HIGH
An exploitable authentication bypass vulnerability exists in the Bluetooth Low Energy (BLE) authentication module of YI M1 Mirrorless Camera V3.2-cn. An attacker can send a set of BLE commands to trigger this vulnerability, resulting in sensitive data leakage (e.g., personal photos). An attacker can also control the camera to record or take a picture after bypassing authentication.