ID

VAR-201802-0523


CVE

CVE-2017-11633


TITLE

Wireless IP Camera 360 Vulnerabilities related to certificate and password management in devices

Trust: 0.8

sources: JVNDB: JVNDB-2017-012792

DESCRIPTION

An issue was discovered on Wireless IP Camera 360 devices. Remote attackers can discover RTSP credentials by connecting to TCP port 9527 and reading the InsertConnect field. 360WirelessIPCamera is a network camera product from Qihu360 of China. There is a security hole in 360WirelessIPCamera

Trust: 2.25

sources: NVD: CVE-2017-11633 // JVNDB: JVNDB-2017-012792 // CNVD: CNVD-2018-06851 // VULHUB: VHN-102075

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-06851

AFFECTED PRODUCTS

vendor: - model:wireless_ip_camera_360scope:eqversion: -

Trust: 1.6

vendor:multiple vendorsmodel: - scope:eqversion:(wireless ip camera 360 device )

Trust: 0.8

vendor:qihoomodel:wireless ip camerascope:eqversion:360

Trust: 0.6

sources: CNVD: CNVD-2018-06851 // JVNDB: JVNDB-2017-012792 // CNNVD: CNNVD-201707-1210 // NVD: CVE-2017-11633

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-11633
value: HIGH

Trust: 1.0

NVD: CVE-2017-11633
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-06851
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201707-1210
value: HIGH

Trust: 0.6

VULHUB: VHN-102075
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-11633
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-06851
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-102075
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-11633
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-06851 // VULHUB: VHN-102075 // JVNDB: JVNDB-2017-012792 // CNNVD: CNNVD-201707-1210 // NVD: CVE-2017-11633

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-255

Trust: 0.9

sources: VULHUB: VHN-102075 // JVNDB: JVNDB-2017-012792 // NVD: CVE-2017-11633

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201707-1210

TYPE

trust management problem

Trust: 0.6

sources: CNNVD: CNNVD-201707-1210

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-012792

EXTERNAL IDS

db:NVDid:CVE-2017-11633

Trust: 3.1

db:JVNDBid:JVNDB-2017-012792

Trust: 0.8

db:CNNVDid:CNNVD-201707-1210

Trust: 0.7

db:CNVDid:CNVD-2018-06851

Trust: 0.6

db:VULHUBid:VHN-102075

Trust: 0.1

sources: CNVD: CNVD-2018-06851 // VULHUB: VHN-102075 // JVNDB: JVNDB-2017-012792 // CNNVD: CNNVD-201707-1210 // NVD: CVE-2017-11633

REFERENCES

url:https://github.com/eloygn/it_security_research_wirelessip_camera_family

Trust: 3.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-11633

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-11633

Trust: 0.8

sources: CNVD: CNVD-2018-06851 // VULHUB: VHN-102075 // JVNDB: JVNDB-2017-012792 // CNNVD: CNNVD-201707-1210 // NVD: CVE-2017-11633

SOURCES

db:CNVDid:CNVD-2018-06851
db:VULHUBid:VHN-102075
db:JVNDBid:JVNDB-2017-012792
db:CNNVDid:CNNVD-201707-1210
db:NVDid:CVE-2017-11633

LAST UPDATE DATE

2024-11-23T22:45:26.783000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-06851date:2018-03-30T00:00:00
db:VULHUBid:VHN-102075date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2017-012792date:2018-04-17T00:00:00
db:CNNVDid:CNNVD-201707-1210date:2019-10-23T00:00:00
db:NVDid:CVE-2017-11633date:2024-11-21T03:08:09.450

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-06851date:2018-03-30T00:00:00
db:VULHUBid:VHN-102075date:2018-02-26T00:00:00
db:JVNDBid:JVNDB-2017-012792date:2018-04-17T00:00:00
db:CNNVDid:CNNVD-201707-1210date:2017-07-26T00:00:00
db:NVDid:CVE-2017-11633date:2018-02-26T22:29:00.290