PT-2022-4498 · Isnex+1 · Isnex Hc-Ip9050Hd+2

Published

2022-08-29

·

Updated

2023-08-08

·

CVE-2022-37680

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Hitachi Kokusai Electric Network products versions prior to the fixed version ISnex HC-IP9100HD version 1.07 and below ISnex HC-IP9050HD version not specified
Description The issue is related to improper authentication for critical functions in Hitachi Kokusai Electric Network products, including monitoring system devices such as cameras, decoders, and encoders. This allows attackers to remotely reboot the device via a crafted POST request to the endpoint "/ptipupgrade.cgi". The vulnerability is associated with inadequate access control, which can be exploited by an attacker to gain full access to the device.
Recommendations For Hitachi Kokusai Electric Network products, update to a version that includes the fixes provided in security information ID hitachi-sec-2022-001. For ISnex HC-IP9100HD version 1.07 and below, update to a version above 1.07. For ISnex HC-IP9050HD, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the "/ptipupgrade.cgi" endpoint until a patch is available.

Missing Authentication

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2022-05365
CVE-2022-37680

Affected Products

Hitachi Kokusai Electric Network Products
Isnex Hc-Ip9050Hd
Isnex Hc-Ip9100Hd