PT-2018-11316 · Sv3C · Sv3C L-Series Hd Camera
Published
2018-10-19
·
Updated
2019-01-28
·
CVE-2018-12666
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SV3C L-SERIES HD CAMERA version 2.3.4.2103-S50-NTD-B20170508B
Description
The issue allows remote attackers to bypass authentication and gain administrator access. This is possible because the device improperly identifies users only by the authentication level sent in the cookies. An attacker can exploit this by setting the
authLevel cookie to 255.Recommendations
For version 2.3.4.2103-S50-NTD-B20170508B, as a temporary workaround, consider restricting access to the device's administrative interface until a patch is available. Avoid relying solely on the
authLevel cookie for authentication. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sv3C L-Series Hd Camera