ID

VAR-201703-1377


TITLE

Wireless IP Camera (P2P) WIFICAM Pre-Authorization Information and Credential Disclosure Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2017-02774

DESCRIPTION

WirelessIPCamera (P2P) WIFICAM is a wireless IP camera. WirelessIPCamera (P2P) WIFICAM pre-authorization information and credential disclosure vulnerability. When accessing the server configuration file, by providing blank \"loginuse\" and \"loginpas\" parameters, the attacker can bypass the device's authentication program and download the device's configuration file without logging in, resulting in the leaked device's credential information, and FTP and SMTP account content.

Trust: 0.6

sources: CNVD: CNVD-2017-02774

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-02774

AFFECTED PRODUCTS

vendor:foscammodel:wireless ip camera wificamscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2017-02774

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-02774
value: HIGH

Trust: 0.6

CNVD: CNVD-2017-02774
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-02774

EXTERNAL IDS

db:CNVDid:CNVD-2017-02774

Trust: 0.6

sources: CNVD: CNVD-2017-02774

REFERENCES

url:http://seclists.org/bugtraq/2017/mar/32

Trust: 0.6

url:https://pierrekim.github.io/blog/2017-03-08-camera-goahead-0day.html?from=timeline&isappinstalled=0

Trust: 0.6

sources: CNVD: CNVD-2017-02774

SOURCES

db:CNVDid:CNVD-2017-02774

LAST UPDATE DATE

2022-05-04T10:22:48.595000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-02774date:2017-03-18T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-02774date:2017-03-18T00:00:00