PT-2019-13799 · Microdigital · Microdigital N-Series

Shaposhnikov Ilya

·

Publicado

2019-08-06

·

Atualizado

2020-08-24

·

CVE-2019-14707

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MicroDigital N-series cameras versions through 6400.0.8.5
Description An issue was discovered in the firmware update process of the affected cameras, which is insecure and can lead to remote code execution. The attacker can provide arbitrary firmware in a .dat file via a webparam?system&action=set&upgrade URI.
Recommendations For versions through 6400.0.8.5, update the firmware to a version later than 6400.0.8.5 to secure the firmware update process and prevent remote code execution. As a temporary workaround, consider restricting access to the webparam?system&action=set&upgrade URI to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-14707

Produtos afetados

Microdigital N-Series