ID

VAR-201610-0711


TITLE

AVTECH device PwdGrp.cgi exists verification command injection vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-08743

DESCRIPTION

AVTECH, founded in 1996, is one of the world's leading manufacturers of CCTV. The main products are monitoring equipment, network cameras, network video recorders and so on. The AVTECH device PwdGrp.cgi has a verification command injection vulnerability. The PwdGrp.cgi script can modify the username, password, and group parameters with unauthenticated or processed system commands to create new or modify users. An attacker exploits a vulnerability to execute arbitrary system commands with root privileges.

Trust: 0.6

sources: CNVD: CNVD-2016-08743

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-08743

AFFECTED PRODUCTS

vendor:avtechmodel:dvrscope: - version: -

Trust: 0.6

vendor:avtechmodel:nvrscope: - version: -

Trust: 0.6

vendor:avtechmodel:ip camerascope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-08743

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-08743
value: HIGH

Trust: 0.6

CNVD: CNVD-2016-08743
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-08743

EXTERNAL IDS

db:CNVDid:CNVD-2016-08743

Trust: 0.6

sources: CNVD: CNVD-2016-08743

REFERENCES

url:http://seclists.org/bugtraq/2016/oct/26

Trust: 0.6

url:http://www.search-lab.hu/advisories/126-avtech-devices-multiple-vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2016-08743

SOURCES

db:CNVDid:CNVD-2016-08743

LAST UPDATE DATE

2022-05-04T09:43:54.311000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-08743date:2016-11-02T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-08743date:2016-10-13T00:00:00