PT-2020-7391 · Zavio · Zavio Ip Cameras

Fernando Miranda

+2

·

Published

2020-01-29

·

Updated

2020-02-01

·

CVE-2013-2567

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Zavio IP Cameras versions 1.6.03 and earlier
Description: An Authentication Bypass issue exists in the web interface of Zavio IP Cameras due to a hardcoded admin account found in boa.conf. This allows a remote malicious user to obtain sensitive information.
Recommendations: For versions 1.6.03 and earlier, consider disabling the web interface until a patch is available to prevent exploitation of the hardcoded admin account. Restrict access to the boa.conf file to minimize the risk of sensitive information disclosure. Avoid using the default admin account in the affected Zavio IP Cameras until the issue is resolved.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2567

Affected Products

Zavio Ip Cameras