PT-2019-13799 · Microdigital · Microdigital N-Series

Shaposhnikov Ilya

·

Published

2019-08-06

·

Updated

2020-08-24

·

CVE-2019-14707

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MicroDigital N-series cameras versions through 6400.0.8.5
Description An issue was discovered in the firmware update process of the affected cameras, which is insecure and can lead to remote code execution. The attacker can provide arbitrary firmware in a .dat file via a webparam?system&action=set&upgrade URI.
Recommendations For versions through 6400.0.8.5, update the firmware to a version later than 6400.0.8.5 to secure the firmware update process and prevent remote code execution. As a temporary workaround, consider restricting access to the webparam?system&action=set&upgrade URI to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-14707

Affected Products

Microdigital N-Series