CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.9. It may be remotely exploitable.
CVE
CVE-2017-8865
Severity
MEDIUM
CVSS
5.9
EPSS
0.83%
Original NVD Description
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 do not provide sufficient protections against capture-replay attacks, allowing an attacker on the network to replay VoIP traffic between a Dino device and remote server to any other Dino device.
Related CVEs
Other vulnerabilities affecting the same vendor(s)