PT-2019-12733 · Vstarcam · Vstarcam 200V+1
Publicado
2019-05-23
·
Atualizado
2021-09-13
·
CVE-2019-12288
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VStarcam 100T (C7824WIP) version KR75.8.53.20
VStarcam 200V (C38S) version KR203.18.1.20
Description
An issue allows manipulation of the web service, network, and account files through a web UI firmware update without any authentication. This can be achieved by an attacker through a manipulated web UI firmware update, allowing access to the device.
Recommendations
For VStarcam 100T (C7824WIP) version KR75.8.53.20, consider restricting access to the firmware update feature until a fix is available.
For VStarcam 200V (C38S) version KR203.18.1.20, consider restricting access to the firmware update feature until a fix is available.
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vstarcam 100T
Vstarcam 200V