ID

VAR-201401-0731


TITLE

3S Multiple IP Video Server Default Administrator Credentials Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2014-00498

DESCRIPTION

3S S2071 (USB and SD card interface) performance dual video server H.264/MJPEG encoding, can simultaneously output D1, CIF, QCIF three streams, Full D1 resolution, 25 frames per second / PAL, deinterlacing, Support a variety of PTZ control protocols, alarm input x2, alarm output x1, USB interface can be connected to the external hard disk. The 3S S2071 and S4071 IP video servers are installed with default user credentials, and the password accounts for 'root' and '3 SADMIN' have '27988303' and form a file password that allows remote attackers to gain access to the device.

Trust: 0.6

sources: CNVD: CNVD-2014-00498

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-00498

AFFECTED PRODUCTS

vendor:3s pocketnet techmodel:s2071 1.04 std-1scope: - version: -

Trust: 0.6

vendor:3s pocketnet techmodel:s4071 1.04 std-1scope: - version: -

Trust: 0.6

vendor:3s pocketnet techmodel:s4071 1.03 std-1scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2014-00498

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-00498
value: HIGH

Trust: 0.6

CNVD: CNVD-2014-00498
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-00498

PATCH

title:3S multiple IP video server default administrator credential vulnerability patchurl:https://www.cnvd.org.cn/patchinfo/show/42827

Trust: 0.6

sources: CNVD: CNVD-2014-00498

EXTERNAL IDS

db:OSVDBid:102268

Trust: 0.6

db:CNVDid:CNVD-2014-00498

Trust: 0.6

sources: CNVD: CNVD-2014-00498

REFERENCES

url:http://osvdb.org/show/osvdb/102268

Trust: 0.6

url:http://dariusfreamon.wordpress.com/2014/01/18/s3-s2071-s4071-ip-video-server-web-interface-default-admin-credentials/

Trust: 0.6

sources: CNVD: CNVD-2014-00498

SOURCES

db:CNVDid:CNVD-2014-00498

LAST UPDATE DATE

2022-05-17T02:07:13.676000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-00498date:2014-01-22T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-00498date:2014-01-22T00:00:00