ID

VAR-201811-0736


CVE

CVE-2018-19075


TITLE

Foscam C2 Device and Opticam i5 Information disclosure vulnerability in devices

Trust: 0.8

sources: JVNDB: JVNDB-2018-011673

DESCRIPTION

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The firewall feature makes it easier for remote attackers to ascertain credentials and firewall rules because invalid credentials lead to error -2, whereas rule-based blocking leads to error -8. Foscam C2 Device and Opticam i5 The device contains an information disclosure vulnerability.Information may be obtained. Both Foscam C2 and Opticami 5 are network camera products from China Foscom (FOSCAM)

Trust: 2.25

sources: NVD: CVE-2018-19075 // JVNDB: JVNDB-2018-011673 // CNVD: CNVD-2019-04043 // VULHUB: VHN-129698

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-04043

AFFECTED PRODUCTS

vendor:opticammodel:i5 applicationscope:eqversion:2.21.1.128

Trust: 2.4

vendor:opticammodel:i5 systemscope:eqversion:1.5.2.11

Trust: 2.4

vendor:foscammodel:c2 applicationscope:eqversion:2.72.1.32

Trust: 1.8

vendor:foscammodel:c2 systemscope:eqversion:1.11.1.8

Trust: 1.8

vendor:foscammodel:c2 devices with systemscope:eqversion:1.11.1.8

Trust: 0.6

vendor:foscammodel:c2 devices with applicationscope:eqversion:2.72.1.32

Trust: 0.6

vendor:foscammodel:opticam i5 devices with systemscope:eqversion:1.5.2.11

Trust: 0.6

vendor:foscammodel:opticam i5 devices with applicationscope:eqversion:2.21.1.128

Trust: 0.6

sources: CNVD: CNVD-2019-04043 // JVNDB: JVNDB-2018-011673 // CNNVD: CNNVD-201811-152 // NVD: CVE-2018-19075

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-19075
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-19075
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2019-04043
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201811-152
value: MEDIUM

Trust: 0.6

VULHUB: VHN-129698
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-19075
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-04043
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-129698
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-19075
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-04043 // VULHUB: VHN-129698 // JVNDB: JVNDB-2018-011673 // CNNVD: CNNVD-201811-152 // NVD: CVE-2018-19075

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-129698 // JVNDB: JVNDB-2018-011673 // NVD: CVE-2018-19075

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201811-152

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201811-152

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-011673

PATCH

title:C2url:https://www.foscam.com/C2.html

Trust: 0.8

sources: JVNDB: JVNDB-2018-011673

EXTERNAL IDS

db:NVDid:CVE-2018-19075

Trust: 3.1

db:JVNDBid:JVNDB-2018-011673

Trust: 0.8

db:CNNVDid:CNNVD-201811-152

Trust: 0.7

db:CNVDid:CNVD-2019-04043

Trust: 0.6

db:VULHUBid:VHN-129698

Trust: 0.1

sources: CNVD: CNVD-2019-04043 // VULHUB: VHN-129698 // JVNDB: JVNDB-2018-011673 // CNNVD: CNNVD-201811-152 // NVD: CVE-2018-19075

REFERENCES

url:https://sintonen.fi/advisories/foscam-ip-camera-multiple-vulnerabilities.txt

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2018-19075

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-19075

Trust: 0.8

url:https://www.verkkokauppa.com/fi/product/52328/fcqxq/opticam-i5-hd-ip-kamera

Trust: 0.8

sources: CNVD: CNVD-2019-04043 // VULHUB: VHN-129698 // JVNDB: JVNDB-2018-011673 // CNNVD: CNNVD-201811-152 // NVD: CVE-2018-19075

SOURCES

db:CNVDid:CNVD-2019-04043
db:VULHUBid:VHN-129698
db:JVNDBid:JVNDB-2018-011673
db:CNNVDid:CNNVD-201811-152
db:NVDid:CVE-2018-19075

LAST UPDATE DATE

2024-11-23T22:12:13.427000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-04043date:2019-02-13T00:00:00
db:VULHUBid:VHN-129698date:2018-12-11T00:00:00
db:JVNDBid:JVNDB-2018-011673date:2019-01-18T00:00:00
db:CNNVDid:CNNVD-201811-152date:2018-11-08T00:00:00
db:NVDid:CVE-2018-19075date:2024-11-21T03:57:17.123

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-04043date:2019-02-13T00:00:00
db:VULHUBid:VHN-129698date:2018-11-07T00:00:00
db:JVNDBid:JVNDB-2018-011673date:2019-01-18T00:00:00
db:CNNVDid:CNNVD-201811-152date:2018-11-08T00:00:00
db:NVDid:CVE-2018-19075date:2018-11-07T18:29:04.697