ID

VAR-201811-0737


CVE

CVE-2018-19076


TITLE

Foscam C2 Device and Opticam i5 Authentication vulnerabilities in devices

Trust: 0.8

sources: JVNDB: JVNDB-2018-011672

DESCRIPTION

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The FTP and RTSP services make it easier for attackers to conduct brute-force authentication attacks, because failed-authentication limits apply only to HTTP (not FTP or RTSP). Foscam C2 Device and Opticam i5 The device contains an authentication vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Both Foscam C2 and Opticami 5 are network camera products from China Foscom (FOSCAM). A violent authentication attack vulnerability exists in the FoscamC2 and Opticami5 devices, which can be exploited by remote attackers to enforce brute force attacks. Security vulnerabilities exist in Foscam C2 and Opticam i5 devices

Trust: 2.25

sources: NVD: CVE-2018-19076 // JVNDB: JVNDB-2018-011672 // CNVD: CNVD-2019-04042 // VULHUB: VHN-129699

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-04042

AFFECTED PRODUCTS

vendor:foscammodel:c2 systemscope:eqversion:1.11.1.8

Trust: 2.4

vendor:foscammodel:c2 applicationscope:eqversion:2.72.1.32

Trust: 1.8

vendor:opticammodel:i5 applicationscope:eqversion:2.21.1.128

Trust: 1.8

vendor:opticammodel:i5 systemscope:eqversion:1.5.2.11

Trust: 1.8

vendor:foscammodel:c2 devices with systemscope:eqversion:1.11.1.8

Trust: 0.6

vendor:foscammodel:c2 devices with applicationscope:eqversion:2.72.1.32

Trust: 0.6

vendor:foscammodel:opticam i5 devices with systemscope:eqversion:1.5.2.11

Trust: 0.6

vendor:foscammodel:opticam i5 devices with applicationscope:eqversion:2.21.1.128

Trust: 0.6

sources: CNVD: CNVD-2019-04042 // JVNDB: JVNDB-2018-011672 // CNNVD: CNNVD-201811-153 // NVD: CVE-2018-19076

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-19076
value: CRITICAL

Trust: 1.0

NVD: CVE-2018-19076
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2019-04042
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201811-153
value: MEDIUM

Trust: 0.6

VULHUB: VHN-129699
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-19076
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-04042
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-129699
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-19076
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-04042 // VULHUB: VHN-129699 // JVNDB: JVNDB-2018-011672 // CNNVD: CNNVD-201811-153 // NVD: CVE-2018-19076

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.9

sources: VULHUB: VHN-129699 // JVNDB: JVNDB-2018-011672 // NVD: CVE-2018-19076

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201811-153

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201811-153

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-011672

PATCH

title:C2url:https://www.foscam.com/C2.html

Trust: 0.8

sources: JVNDB: JVNDB-2018-011672

EXTERNAL IDS

db:NVDid:CVE-2018-19076

Trust: 3.1

db:JVNDBid:JVNDB-2018-011672

Trust: 0.8

db:CNNVDid:CNNVD-201811-153

Trust: 0.7

db:CNVDid:CNVD-2019-04042

Trust: 0.6

db:VULHUBid:VHN-129699

Trust: 0.1

sources: CNVD: CNVD-2019-04042 // VULHUB: VHN-129699 // JVNDB: JVNDB-2018-011672 // CNNVD: CNNVD-201811-153 // NVD: CVE-2018-19076

REFERENCES

url:https://sintonen.fi/advisories/foscam-ip-camera-multiple-vulnerabilities.txt

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2018-19076

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-19076

Trust: 0.8

url:https://www.verkkokauppa.com/fi/product/52328/fcqxq/opticam-i5-hd-ip-kamera

Trust: 0.8

sources: CNVD: CNVD-2019-04042 // VULHUB: VHN-129699 // JVNDB: JVNDB-2018-011672 // CNNVD: CNNVD-201811-153 // NVD: CVE-2018-19076

SOURCES

db:CNVDid:CNVD-2019-04042
db:VULHUBid:VHN-129699
db:JVNDBid:JVNDB-2018-011672
db:CNNVDid:CNNVD-201811-153
db:NVDid:CVE-2018-19076

LAST UPDATE DATE

2024-11-23T23:11:58.160000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-04042date:2019-02-13T00:00:00
db:VULHUBid:VHN-129699date:2018-12-11T00:00:00
db:JVNDBid:JVNDB-2018-011672date:2019-01-18T00:00:00
db:CNNVDid:CNNVD-201811-153date:2018-11-08T00:00:00
db:NVDid:CVE-2018-19076date:2024-11-21T03:57:17.287

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-04042date:2019-02-13T00:00:00
db:VULHUBid:VHN-129699date:2018-11-07T00:00:00
db:JVNDBid:JVNDB-2018-011672date:2019-01-18T00:00:00
db:CNNVDid:CNNVD-201811-153date:2018-11-08T00:00:00
db:NVDid:CVE-2018-19076date:2018-11-07T18:29:05.070