PT-2022-4498 · Isnex+1 · Isnex Hc-Ip9050Hd+2
Published
2022-08-29
·
Updated
2023-08-08
·
CVE-2022-37680
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Hitachi Kokusai Electric Network products versions prior to the fixed version
ISnex HC-IP9100HD version 1.07 and below
ISnex HC-IP9050HD version not specified
Description
The issue is related to improper authentication for critical functions in Hitachi Kokusai Electric Network products, including monitoring system devices such as cameras, decoders, and encoders. This allows attackers to remotely reboot the device via a crafted POST request to the endpoint "/ptipupgrade.cgi". The vulnerability is associated with inadequate access control, which can be exploited by an attacker to gain full access to the device.
Recommendations
For Hitachi Kokusai Electric Network products, update to a version that includes the fixes provided in security information ID hitachi-sec-2022-001.
For ISnex HC-IP9100HD version 1.07 and below, update to a version above 1.07.
For ISnex HC-IP9050HD, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to the "/ptipupgrade.cgi" endpoint until a patch is available.
Missing Authentication
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hitachi Kokusai Electric Network Products
Isnex Hc-Ip9050Hd
Isnex Hc-Ip9100Hd