ID

VAR-201610-0725


TITLE

AVTECH device has a plaintext storage password vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-08707

DESCRIPTION

AVTECH, founded in 1996, is one of the world's leading manufacturers of CCTV. The main products are monitoring equipment, network cameras, network video recorders and so on. There is a plaintext storage password vulnerability in AVTECH devices. The attacker can use the vulnerability to obtain the user password through command injection or authentication bypass, which constitutes the risk of information leakage.

Trust: 0.6

sources: CNVD: CNVD-2016-08707

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-08707

AFFECTED PRODUCTS

vendor:avtechmodel:dvrscope: - version: -

Trust: 0.6

vendor:avtechmodel:nvrscope: - version: -

Trust: 0.6

vendor:avtechmodel:ip camerascope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-08707

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-08707
value: HIGH

Trust: 0.6

CNVD: CNVD-2016-08707
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-08707

EXTERNAL IDS

db:CNVDid:CNVD-2016-08707

Trust: 0.6

sources: CNVD: CNVD-2016-08707

REFERENCES

url:http://seclists.org/bugtraq/2016/oct/26

Trust: 0.6

url:http://www.search-lab.hu/advisories/126-avtech-devices-multiple-vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2016-08707

SOURCES

db:CNVDid:CNVD-2016-08707

LAST UPDATE DATE

2022-05-04T10:19:38.750000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-08707date:2016-10-12T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-08707date:2016-10-12T00:00:00