PT-2016-7671 · Siemens · Cfis1425+15

Published

2016-11-22

·

Updated

2016-12-23

·

CVE-2016-9155

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SIEMENS IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 versions prior to 1.41 SP18 S1 SIEMENS IP Camera Models CCPW3025, CCPW5025 versions prior to 0.1.73 S1 SIEMENS IP Camera Models CCMD3025-DN18 versions prior to v1.394 S1 SIEMENS IP Camera Models CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, CCIS1425, CFMS2025, CCMS2025, CVMS2025-IR, CFMW1025, CCMW1025 versions prior to v2635 SP1
Description The issue allows an attacker with network access to the web server to obtain administrative credentials under certain circumstances.
Recommendations For SIEMENS IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025, update to version 1.41 SP18 S1 or later. For SIEMENS IP Camera Models CCPW3025, CCPW5025, update to version 0.1.73 S1 or later. For SIEMENS IP Camera Models CCMD3025-DN18, update to version v1.394 S1 or later. For SIEMENS IP Camera Models CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, CCIS1425, CFMS2025, CCMS2025, CVMS2025-IR, CFMW1025, CCMW1025, update to version v2635 SP1 or later.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9155

Affected Products

Ccid1145-Dn36
Ccid1445-Dn18
Ccid1445-Dn28
Ccis1425
Ccmd3025-Dn18
Ccms2025
Ccmw1025
Ccmw3025
Ccpw3025
Ccpw5025
Cfis1425
Cfms2025
Cfmw1025
Cfmw3025
Cvms2025-Ir
Cvmw3025-Ir