PT-2019-12733 · Vstarcam · Vstarcam 200V+1

Publicado

2019-05-23

·

Atualizado

2021-09-13

·

CVE-2019-12288

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VStarcam 100T (C7824WIP) version KR75.8.53.20 VStarcam 200V (C38S) version KR203.18.1.20
Description An issue allows manipulation of the web service, network, and account files through a web UI firmware update without any authentication. This can be achieved by an attacker through a manipulated web UI firmware update, allowing access to the device.
Recommendations For VStarcam 100T (C7824WIP) version KR75.8.53.20, consider restricting access to the firmware update feature until a fix is available. For VStarcam 200V (C38S) version KR203.18.1.20, consider restricting access to the firmware update feature until a fix is available.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12288

Produtos afetados

Vstarcam 100T
Vstarcam 200V