ID

VAR-201802-1412


TITLE

Multiple remote vulnerabilities in Geovision IP camera devices

Trust: 0.6

sources: CNVD: CNVD-2018-03053

DESCRIPTION

Geovision is a Taiwan-based company that specializes in digital security surveillance systems, providing core applications such as image capture, image analysis, image compression, and image processing to provide customers with smart applications and best-in-class monitoring solutions. The GV-BX1500 and GV-MFD1501 are two cameras from Geovision. The GeovisionIP camera device has leaked configuration information, username and password to modify admin privileges, and remote command execution vulnerabilities. The attacker can use the vulnerability to obtain all the configuration information of the device, obtain and modify the original account information and execute the command remotely, and successfully getshell.

Trust: 0.6

sources: CNVD: CNVD-2018-03053

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-03053

AFFECTED PRODUCTS

vendor:geovisionmodel:gv-bx1500scope: - version: -

Trust: 0.6

vendor:geovisionmodel:gv-mfd1501scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2018-03053

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2018-03053
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-03053
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2018-03053

PATCH

title:GeovisionIP camera device has multiple patches for remote vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/116075

Trust: 0.6

sources: CNVD: CNVD-2018-03053

EXTERNAL IDS

db:CNVDid:CNVD-2018-03053

Trust: 0.6

sources: CNVD: CNVD-2018-03053

REFERENCES

url:https://github.com/mcw0/poc/blob/master/geovision%20ip%20camera%20multiple

Trust: 0.6

sources: CNVD: CNVD-2018-03053

SOURCES

db:CNVDid:CNVD-2018-03053

LAST UPDATE DATE

2022-05-04T09:33:54.240000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-03053date:2018-02-18T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-03053date:2018-02-09T00:00:00