PT-2016-7671 · Siemens · Cfis1425+15
Published
2016-11-22
·
Updated
2016-12-23
·
CVE-2016-9155
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SIEMENS IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 versions prior to 1.41 SP18 S1
SIEMENS IP Camera Models CCPW3025, CCPW5025 versions prior to 0.1.73 S1
SIEMENS IP Camera Models CCMD3025-DN18 versions prior to v1.394 S1
SIEMENS IP Camera Models CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, CCIS1425, CFMS2025, CCMS2025, CVMS2025-IR, CFMW1025, CCMW1025 versions prior to v2635 SP1
Description
The issue allows an attacker with network access to the web server to obtain administrative credentials under certain circumstances.
Recommendations
For SIEMENS IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025, update to version 1.41 SP18 S1 or later.
For SIEMENS IP Camera Models CCPW3025, CCPW5025, update to version 0.1.73 S1 or later.
For SIEMENS IP Camera Models CCMD3025-DN18, update to version v1.394 S1 or later.
For SIEMENS IP Camera Models CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, CCIS1425, CFMS2025, CCMS2025, CVMS2025-IR, CFMW1025, CCMW1025, update to version v2635 SP1 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ccid1145-Dn36
Ccid1445-Dn18
Ccid1445-Dn28
Ccis1425
Ccmd3025-Dn18
Ccms2025
Ccmw1025
Ccmw3025
Ccpw3025
Ccpw5025
Cfis1425
Cfms2025
Cfmw1025
Cfmw3025
Cvms2025-Ir
Cvmw3025-Ir