PT-2018-13623 · Amcrest · Amcrest Networked Devices

Jack M. Mckenna

·

Published

2018-09-05

·

Updated

2019-10-03

·

CVE-2018-16546

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Amcrest networked devices (affected versions not specified)
Description The issue concerns Amcrest networked devices using the same hardcoded SSL private key across different installations. This allows remote attackers to bypass cryptographic protection by leveraging knowledge of the key from another installation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16546

Affected Products

Amcrest Networked Devices