PT-2019-13799 · Microdigital · Microdigital N-Series
Shaposhnikov Ilya
·
Published
2019-08-06
·
Updated
2020-08-24
·
CVE-2019-14707
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MicroDigital N-series cameras versions through 6400.0.8.5
Description
An issue was discovered in the firmware update process of the affected cameras, which is insecure and can lead to remote code execution. The attacker can provide arbitrary firmware in a
.dat file via a webparam?system&action=set&upgrade URI.Recommendations
For versions through 6400.0.8.5, update the firmware to a version later than 6400.0.8.5 to secure the firmware update process and prevent remote code execution. As a temporary workaround, consider restricting access to the
webparam?system&action=set&upgrade URI to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Microdigital N-Series