ID

VAR-201811-0741


CVE

CVE-2018-19080


TITLE

Foscam Opticam i5 Cross-Site Scripting Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2018-22820 // CNNVD: CNNVD-201811-157

DESCRIPTION

An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetHostname method allows unauthenticated persistent XSS. FoscamOpticami5 is an IP camera from Foscom (FOSCAM). An unauthenticated attacker can exploit this vulnerability for cross-site scripting attacks

Trust: 2.25

sources: NVD: CVE-2018-19080 // JVNDB: JVNDB-2018-011908 // CNVD: CNVD-2018-22820 // VULHUB: VHN-129704

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-22820

AFFECTED PRODUCTS

vendor:opticammodel:i5 applicationscope:eqversion:2.21.1.128

Trust: 2.4

vendor:opticammodel:i5 systemscope:eqversion:1.5.2.11

Trust: 2.4

vendor:foscammodel:c2 applicationscope:eqversion:2.72.1.32

Trust: 1.0

vendor:foscammodel:c2 systemscope:eqversion:1.11.1.8

Trust: 1.0

vendor:foscammodel:c2 applicationscope: - version: -

Trust: 0.8

vendor:foscammodel:c2 systemscope: - version: -

Trust: 0.8

vendor:foscammodel:opticam i5 applicationscope:eqversion:2.21.1.128

Trust: 0.6

vendor:foscammodel:opticam i5 systemscope:eqversion:1.5.2.11

Trust: 0.6

sources: CNVD: CNVD-2018-22820 // JVNDB: JVNDB-2018-011908 // CNNVD: CNNVD-201811-157 // NVD: CVE-2018-19080

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-19080
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-19080
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2018-22820
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201811-157
value: MEDIUM

Trust: 0.6

VULHUB: VHN-129704
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-19080
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-22820
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-129704
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-19080
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-22820 // VULHUB: VHN-129704 // JVNDB: JVNDB-2018-011908 // CNNVD: CNNVD-201811-157 // NVD: CVE-2018-19080

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-129704 // JVNDB: JVNDB-2018-011908 // NVD: CVE-2018-19080

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201811-157

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201811-157

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-011908

PATCH

title:C2url:https://www.foscam.com/C2.html

Trust: 0.8

sources: JVNDB: JVNDB-2018-011908

EXTERNAL IDS

db:NVDid:CVE-2018-19080

Trust: 3.1

db:JVNDBid:JVNDB-2018-011908

Trust: 0.8

db:CNNVDid:CNNVD-201811-157

Trust: 0.7

db:CNVDid:CNVD-2018-22820

Trust: 0.6

db:VULHUBid:VHN-129704

Trust: 0.1

sources: CNVD: CNVD-2018-22820 // VULHUB: VHN-129704 // JVNDB: JVNDB-2018-011908 // CNNVD: CNNVD-201811-157 // NVD: CVE-2018-19080

REFERENCES

url:https://sintonen.fi/advisories/foscam-ip-camera-multiple-vulnerabilities.txt

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2018-19080

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-19080

Trust: 0.8

url:https://www.verkkokauppa.com/fi/product/52328/fcqxq/opticam-i5-hd-ip-kamera

Trust: 0.8

sources: CNVD: CNVD-2018-22820 // VULHUB: VHN-129704 // JVNDB: JVNDB-2018-011908 // CNNVD: CNNVD-201811-157 // NVD: CVE-2018-19080

SOURCES

db:CNVDid:CNVD-2018-22820
db:VULHUBid:VHN-129704
db:JVNDBid:JVNDB-2018-011908
db:CNNVDid:CNNVD-201811-157
db:NVDid:CVE-2018-19080

LAST UPDATE DATE

2024-11-23T22:38:01.678000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-22820date:2018-11-09T00:00:00
db:VULHUBid:VHN-129704date:2018-12-13T00:00:00
db:JVNDBid:JVNDB-2018-011908date:2019-01-24T00:00:00
db:CNNVDid:CNNVD-201811-157date:2018-11-08T00:00:00
db:NVDid:CVE-2018-19080date:2024-11-21T03:57:17.940

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-22820date:2018-11-09T00:00:00
db:VULHUBid:VHN-129704date:2018-11-07T00:00:00
db:JVNDBid:JVNDB-2018-011908date:2019-01-24T00:00:00
db:CNNVDid:CNNVD-201811-157date:2018-11-08T00:00:00
db:NVDid:CVE-2018-19080date:2018-11-07T18:29:06.807