PT-2019-13797 · Apache+1 · Httpd+1

Shaposhnikov Ilya

·

Published

2019-08-06

·

Updated

2019-08-14

·

CVE-2019-14704

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MicroDigital N-series cameras firmware through 6400.0.8.5
Description A Server-Side Request Forgery (SSRF) issue was found in HTTPD on the affected cameras. This issue can be triggered via FTP commands when a newline character is included in the uploadfile field.
Recommendations For firmware through 6400.0.8.5, consider restricting access to the FTP upload functionality until a patch is available. As a temporary workaround, avoid using the uploadfile field with newline characters in FTP commands.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14704

Affected Products

Httpd
Microdigital N-Series