PT-2017-2639 · Vivotek · Vivotek Network Camera Fd816Ba+2

Publicado

2017-06-23

·

Atualizado

2019-10-03

·

CVE-2017-9828

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VIVOTEK Network Camera IB8369, FD8164, and FD816BA (affected versions not specified)
Description The issue is related to insufficient input processing in the /cgi-bin/admin/testserver.cgi web service of the network camera's firmware. This allows a remote attacker to execute any shell command with superuser privileges by sending a specially crafted HTTP request that uses shell metacharacters in the senderemail parameter.
Recommendations For VIVOTEK Network Camera IB8369, FD8164, and FD816BA, consider disabling the /cgi-bin/admin/testserver.cgi endpoint until a patch is available to prevent exploitation. Restrict access to the senderemail parameter in the affected API endpoint to minimize the risk of shell command injection. Avoid using the senderemail parameter in the /cgi-bin/admin/testserver.cgi endpoint until the issue is resolved.

Correção

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-01866
CVE-2017-9828

Produtos afetados

Vivotek Network Camera Fd8164
Vivotek Network Camera Fd816Ba
Vivotek Network Camera Ib8369