CVE-2018-20956
Swann
- Published
- 8 August 2019
- Last modified
- 17 June 2026
- CVSS
- 5.5 v3.0
- Severity
- medium
- EPSS
- 0.4% (37th pct)
- CISA KEV
- Not listed
- NVD status
- Modified
- Weaknesses
- CWE-532
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by 2020-08-31.
Exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 0.4% probability of exploitation activity in the next 30 days.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| Swwhd-intcam-hd | Swann | unknown | — |
References
- https://www.pentestpartners.com/security-blog/hacking-swann-home-security-camera-video/ exploit
- https://www.swann.com/au/safe-by-swann-upgrade
- https://www.pentestpartners.com/security-blog/hacking-swann-home-security-camera-video/ exploit
- https://www.swann.com/au/safe-by-swann-upgrade
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.