PT-2018-11316 · Sv3C · Sv3C L-Series Hd Camera
Publicado
2018-10-19
·
Atualizado
2019-01-28
·
CVE-2018-12666
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SV3C L-SERIES HD CAMERA version 2.3.4.2103-S50-NTD-B20170508B
Description
The issue allows remote attackers to bypass authentication and gain administrator access. This is possible because the device improperly identifies users only by the authentication level sent in the cookies. An attacker can exploit this by setting the
authLevel cookie to 255.Recommendations
For version 2.3.4.2103-S50-NTD-B20170508B, as a temporary workaround, consider restricting access to the device's administrative interface until a patch is available. Avoid relying solely on the
authLevel cookie for authentication. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sv3C L-Series Hd Camera