CVE-2024-34896: n/a
An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access to live video feed.
AI Analysis
Technical Summary
CVE-2024-34896 describes a security flaw in the Nedis SmartLife Video Doorbell (model WIFICDP10GY) and its iOS application version 1.4.0. The vulnerability permits users who have lost connection to the device via a peer-to-peer link to retain access to the live video feed, potentially exposing sensitive video data. The CVSS v3.1 base score is 7.5, indicating a high severity with network attack vector, low attack complexity, no privileges required, no user interaction, and high confidentiality impact but no integrity or availability impact. No official patch or remediation guidance is currently documented.
Potential Impact
Unauthorized users who were previously connected to the device can continue to view the live video feed even after disconnection, leading to a breach of confidentiality. There is no impact on integrity or availability reported. This could result in privacy violations and unauthorized surveillance.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider restricting access to the device, monitoring connected users, or disabling remote access features if possible. No vendor advisory or official fix has been published at this time.
CVE-2024-34896: n/a
Description
An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access to live video feed.
CVSS v3.1
Score 7.5high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-34896 describes a security flaw in the Nedis SmartLife Video Doorbell (model WIFICDP10GY) and its iOS application version 1.4.0. The vulnerability permits users who have lost connection to the device via a peer-to-peer link to retain access to the live video feed, potentially exposing sensitive video data. The CVSS v3.1 base score is 7.5, indicating a high severity with network attack vector, low attack complexity, no privileges required, no user interaction, and high confidentiality impact but no integrity or availability impact. No official patch or remediation guidance is currently documented.
Potential Impact
Unauthorized users who were previously connected to the device can continue to view the live video feed even after disconnection, leading to a breach of confidentiality. There is no impact on integrity or availability reported. This could result in privacy violations and unauthorized surveillance.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider restricting access to the device, monitoring connected users, or disabling remote access features if possible. No vendor advisory or official fix has been published at this time.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2024-05-09T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a49b1cc27e9c79719a8a455
Added to database: 07/05/2026, 01:22:20 UTC
Last enriched: 07/12/2026, 08:32:10 UTC
Last updated: 09/10/2026, 19:36:48 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.