ID

VAR-201706-1147


TITLE

Foscam camera ONVIF GetStreamUri Administrator Credential Disclosure Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2017-08908

DESCRIPTION

Foscamcamera is a webcam that can push messages to mobile phones and directly implement video Baidu cloud storage via WIFI. There is an administrator credential disclosure vulnerability in FoscamcameraONVIFGetStreamUri, and the Foscam camera device uses the interface of the ONVIF protocol to allow anonymous access. An unauthenticated attacker can extract the administrator username and password via the \"media\" GetStreamUri method. This vulnerability only exists in some devices or parts of the firmware version.

Trust: 0.6

sources: CNVD: CNVD-2017-08908

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-08908

AFFECTED PRODUCTS

vendor:foscammodel:c2scope: - version: -

Trust: 0.6

vendor:foscammodel:sabscope: - version: -

Trust: 0.6

vendor:foscammodel:ebodescope: - version: -

Trust: 0.6

vendor:foscammodel:ivuescope: - version: -

Trust: 0.6

vendor:foscammodel:qcamscope: - version: -

Trust: 0.6

vendor:foscammodel:technaxxscope: - version: -

Trust: 0.6

vendor:foscammodel:nexxtscope: - version: -

Trust: 0.6

vendor:foscammodel:ambientcamscope: - version: -

Trust: 0.6

vendor:foscammodel:novodioscope: - version: -

Trust: 0.6

vendor:foscammodel:turboxscope: - version: -

Trust: 0.6

vendor:foscammodel:netisscope: - version: -

Trust: 0.6

vendor:foscammodel:opticamscope: - version: -

Trust: 0.6

vendor:foscammodel:7linksscope: - version: -

Trust: 0.6

vendor:foscammodel:thomsonscope: - version: -

Trust: 0.6

vendor:foscammodel:chaconscope: - version: -

Trust: 0.6

vendor:foscammodel:opticam i5scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2017-08908

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-08908
value: HIGH

Trust: 0.6

CNVD: CNVD-2017-08908
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-08908

EXTERNAL IDS

db:CNVDid:CNVD-2017-08908

Trust: 0.6

sources: CNVD: CNVD-2017-08908

REFERENCES

url:https://business.f-secure.com/foscam_cameras_and_compromise

Trust: 0.6

url:http://images.news.f-secure.com/web/fsecure/%7b43df9e0d-20a8-404a-86d0-70dcca00b6e5%7d_vulnerabilities-in-foscam-ip-cameras_report.pdf?_ga=2.103952768.1877007297.1496980664-1350286355.1496980664

Trust: 0.6

sources: CNVD: CNVD-2017-08908

SOURCES

db:CNVDid:CNVD-2017-08908

LAST UPDATE DATE

2022-05-04T09:11:25.222000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-08908date:2017-06-09T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-08908date:2017-06-09T00:00:00