PT-2017-3320 · Jooan · Jooan Ip Camera A5

David Sigmundson

+1

·

Publicado

2017-07-31

·

Atualizado

2021-04-20

·

CVE-2017-16566

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jooan IP Camera A5 version 2.3.36
Description The issue is related to an insecure FTP server that does not require authentication, allowing remote attackers to read or replace core system files, including those used for authentication, such as passwd and shadow. This can be exploited to gain full root-level control of the device.
Recommendations For Jooan IP Camera A5 version 2.3.36, consider disabling the FTP server until a patch is available to prevent unauthorized access. Restrict access to the device to minimize the risk of exploitation. Avoid using the device until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00085
CVE-2017-16566

Produtos afetados

Jooan Ip Camera A5