PT-2017-3359 · Acti · Acti Cameras

Mandar Jadhav

·

Publicado

2017-01-20

·

Atualizado

2019-10-09

·

CVE-2017-3184

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ACTi cameras versions A1D-500-V6.11.31-AC
Description The issue is related to inadequate access control in the firmware of ACTi cameras, which can be exploited by a remote attacker. By directly accessing the "http://x.x.x.x/setup/setup maintain firmware-default.html" page, an attacker can perform a factory reset on the device. This can lead to a denial of service condition or allow the attacker to access the device using default credentials.
Recommendations For version A1D-500-V6.11.31-AC, consider restricting access to the factory reset page as a temporary workaround until a patch is available. Avoid using the default credentials in the affected API endpoint until the issue is resolved. As a mitigation measure, restrict access to the setup maintain firmware-default.html page to minimize the risk of exploitation.

Correção

Missing Authentication

Improper Access Control

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00130
CVE-2017-3184

Produtos afetados

Acti Cameras