PT-2019-9558 · Vivotek · Vivotek Network Camera Series

Published

2019-01-03

·

Updated

2019-01-14

·

CVE-2018-18244

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x
Description The issue allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header, which is a result of cross-site scripting in the syslog.html file.
Recommendations For firmware versions 0x06x to 0x08x, consider disabling access to the syslog.html file until a patch is available. Restrict access to the HTTP Referer Header to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18244

Affected Products

Vivotek Network Camera Series