PT-2022-4503 · Isnex+1 · Isnex Hc-Ip9050Hd+2

Published

2022-08-29

·

Updated

2022-11-14

·

CVE-2022-37681

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Hitachi Kokusai Electric Newtork products versions prior to the fixed version ISnex HC-IP9100HD version 1.07 and below ISnex HC-IP9050HD version not specified
Description The issue is related to the /ptippage.cgi component of the network camera video surveillance software, which is associated with incorrect restriction of the path name to a directory with limited access. This can allow a remote attacker to gain full access to the device. The vulnerability can be exploited via a crafted GET request to the /ptippage.cgi endpoint, allowing directory traversal.
Recommendations For ISnex HC-IP9100HD version 1.07 and below: update to a version that contains a fix for the issue. For ISnex HC-IP9050HD: at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /ptippage.cgi endpoint until a patch is available.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2022-05370
CVE-2022-37681

Affected Products

Hitachi Kokusai Electric Network Products
Isnex Hc-Ip9050Hd
Isnex Hc-Ip9100Hd