{ "schema_version": "1.4.0", "id": "GHSA-cc2f-p92p-prhw", "modified": "2022-05-24T16:55:33Z", "published": "2022-05-24T16:55:33Z", "aliases": [ "CVE-2019-13953" ], "details": "An exploitable authentication bypass vulnerability exists in the Bluetooth Low Energy (BLE) authentication module of YI M1 Mirrorless Camera V3.2-cn. An attacker can send a set of BLE commands to trigger this vulnerability, resulting in sensitive data leakage (e.g., personal photos). An attacker can also control the camera to record or take a picture after bypassing authentication.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13953" }, { "type": "WEB", "url": "https://www.cnvd.org.cn/flaw/show/CNVD-2019-23494" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-09-06T16:15:00Z" } }