PT-2020-7391 · Zavio · Zavio Ip Cameras
Fernando Miranda
+2
·
Published
2020-01-29
·
Updated
2020-02-01
·
CVE-2013-2567
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Zavio IP Cameras versions 1.6.03 and earlier
Description:
An Authentication Bypass issue exists in the web interface of Zavio IP Cameras due to a hardcoded admin account found in boa.conf. This allows a remote malicious user to obtain sensitive information.
Recommendations:
For versions 1.6.03 and earlier, consider disabling the web interface until a patch is available to prevent exploitation of the hardcoded admin account.
Restrict access to the boa.conf file to minimize the risk of sensitive information disclosure.
Avoid using the default admin account in the affected Zavio IP Cameras until the issue is resolved.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zavio Ip Cameras