ID

VAR-201612-0630


TITLE

Multiple Sony IPELA Engine IP Cameras Remote Code Execution Vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2016-12612

DESCRIPTION

IPELAEngineIPCameras is an IP camera product from Sony Corporation. There is an unknown remote code execution vulnerability in IPELAEngineIPCameras. An attacker could exploit the vulnerability to execute arbitrary code, and a failed attack attempt could trigger a denial of service condition. Multiple Sony IPELA Engine IP Cameras are prone to unspecified remote code-execution vulnerability. Failed exploit attempts may result in a denial-of-service condition

Trust: 0.81

sources: CNVD: CNVD-2016-12612 // BID: 94840

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-12612

AFFECTED PRODUCTS

vendor:sonymodel:ipela engine ip camerasscope: - version: -

Trust: 0.6

vendor:sonymodel:ipela engine ip camerascope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2016-12612 // BID: 94840

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-12612
value: HIGH

Trust: 0.6

CNVD: CNVD-2016-12612
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-12612

THREAT TYPE

network

Trust: 0.3

sources: BID: 94840

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 94840

EXTERNAL IDS

db:BIDid:94840

Trust: 0.9

db:CNVDid:CNVD-2016-12612

Trust: 0.6

sources: CNVD: CNVD-2016-12612 // BID: 94840

REFERENCES

url:http://www.securityfocus.com/bid/94840

Trust: 0.6

url:www.sony.com

Trust: 0.3

url:http://blog.sec-consult.com/2016/12/backdoor-in-sony-ipela-engine-ip-cameras.html

Trust: 0.3

sources: CNVD: CNVD-2016-12612 // BID: 94840

CREDITS

SEC Consult

Trust: 0.3

sources: BID: 94840

SOURCES

db:CNVDid:CNVD-2016-12612
db:BIDid:94840

LAST UPDATE DATE

2022-05-17T01:43:18.015000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-12612date:2016-12-20T00:00:00
db:BIDid:94840date:2016-12-20T01:08:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-12612date:2016-12-20T00:00:00
db:BIDid:94840date:2016-12-12T00:00:00