PT-2019-13798 · Microdigital · Microdigital N-Series
Shaposhnikov Ilya
·
Publicado
2019-08-06
·
Atualizado
2020-08-24
·
CVE-2019-14705
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MicroDigital N-series cameras versions through 6400.0.8.5
Description
An issue with incorrect access control was found, allowing any valid cookie to be used for making requests as an administrator.
Recommendations
For versions through 6400.0.8.5, consider restricting access to administrative functions until a fix is available. As a temporary workaround, limit the use of cookies for authentication to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Microdigital N-Series