PT-2017-2639 · Vivotek · Vivotek Network Camera Fd816Ba+2
Publicado
2017-06-23
·
Atualizado
2019-10-03
·
CVE-2017-9828
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VIVOTEK Network Camera IB8369, FD8164, and FD816BA (affected versions not specified)
Description
The issue is related to insufficient input processing in the
/cgi-bin/admin/testserver.cgi web service of the network camera's firmware. This allows a remote attacker to execute any shell command with superuser privileges by sending a specially crafted HTTP request that uses shell metacharacters in the senderemail parameter.Recommendations
For VIVOTEK Network Camera IB8369, FD8164, and FD816BA, consider disabling the
/cgi-bin/admin/testserver.cgi endpoint until a patch is available to prevent exploitation.
Restrict access to the senderemail parameter in the affected API endpoint to minimize the risk of shell command injection.
Avoid using the senderemail parameter in the /cgi-bin/admin/testserver.cgi endpoint until the issue is resolved.Correção
OS Command Injection
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Vivotek Network Camera Fd8164
Vivotek Network Camera Fd816Ba
Vivotek Network Camera Ib8369