ID

VAR-201601-0676


TITLE

Haikang camera onvif Protocol authentication is missing

Trust: 0.2

sources: IVD: 68205e14-1e6d-11e6-8415-000c29c12f8f

DESCRIPTION

Hikvision cameras, napshot Interface access does not require authentication, allowing an attacker to directly access the live video image of the camera.

Trust: 0.2

sources: IVD: 68205e14-1e6d-11e6-8415-000c29c12f8f

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 68205e14-1e6d-11e6-8415-000c29c12f8f

AFFECTED PRODUCTS

vendor:hikvisionmodel: - scope:eqversion:;*

Trust: 0.2

sources: IVD: 68205e14-1e6d-11e6-8415-000c29c12f8f

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 68205e14-1e6d-11e6-8415-000c29c12f8f
value: LOW

Trust: 0.2

IVD: 68205e14-1e6d-11e6-8415-000c29c12f8f
severity: LOW
baseScore: 3.3
vectorString: AV:A/AC:L/AU:N/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 6.5
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 68205e14-1e6d-11e6-8415-000c29c12f8f

TYPE

Permission permission and access control

Trust: 0.2

sources: IVD: 68205e14-1e6d-11e6-8415-000c29c12f8f

EXTERNAL IDS

db:IVDid:68205E14-1E6D-11E6-8415-000C29C12F8F

Trust: 0.2

sources: IVD: 68205e14-1e6d-11e6-8415-000c29c12f8f

SOURCES

db:IVDid:68205e14-1e6d-11e6-8415-000c29c12f8f

LAST UPDATE DATE

2022-05-04T10:08:56.347000+00:00


SOURCES UPDATE DATE


SOURCES RELEASE DATE

db:IVDid:68205e14-1e6d-11e6-8415-000c29c12f8fdate:2016-01-24T00:00:00