Viidure Dashcam Android Application
Summary
The Viidure Dashcam Android Application, specifically versions up to 3.3.1.260403, has critical vulnerabilities allowing attackers to access, modify, or delete sensitive user data and system files. The vulnerabilities stem from misconfigured cloud storage with public read permissions and the use of hard-coded credentials.
IFF Assessment
This article details severe vulnerabilities in a widely used dashcam application that expose sensitive user data and system files to attackers, posing a significant risk to users.
Severity
The CVSS score of 10.0 indicates a critical severity, reflecting that the vulnerabilities allow for unauthorized access, modification, and deletion of sensitive data and critical system files, with no complexity for the attacker.
Defender Context
Defenders should be aware of the critical vulnerabilities in the Viidure Dashcam Android Application, particularly concerning misconfigured cloud storage and hard-coded credentials. This highlights the ongoing risk of data exposure from IoT devices and the importance of secure cloud storage configurations.