PT-2017-15699 · Acti · Acti Cameras

Mandar Jadhav

·

Publicado

2017-12-15

·

Atualizado

2019-10-09

·

CVE-2017-3185

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ACTi cameras including the D, B, I, and E series version A1D-500-V6.11.31-AC
Description The web application in the affected cameras uses the GET method to process requests containing sensitive information, such as user account name and password. This can expose the sensitive information through the browser's history, referrers, web logs, and other sources.
Recommendations For version A1D-500-V6.11.31-AC, consider changing the request method from GET to POST to prevent sensitive information from being exposed in the browser's history and web logs. As a temporary workaround, restrict access to the web application to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-3185

Produtos afetados

Acti Cameras