ID

VAR-201811-0822


CVE

CVE-2018-19065


TITLE

Foscam C2 Device and Opticam i5 Vulnerabilities related to the use of hard-coded credentials on devices

Trust: 0.8

sources: JVNDB: JVNDB-2018-011650

DESCRIPTION

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The exported device configuration is encrypted with the hardcoded BpP+2R9*Q password in some cases. Foscam C2 Device and Opticam i5 The device contains a vulnerability related to the use of hard-coded credentials.Information may be obtained. Both Foscam C2 and Opticami 5 are network camera products from China Foscom (FOSCAM). An information disclosure vulnerability exists in the FoscamC2 and Opticami5 devices

Trust: 2.25

sources: NVD: CVE-2018-19065 // JVNDB: JVNDB-2018-011650 // CNVD: CNVD-2019-04054 // VULHUB: VHN-129687

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-04054

AFFECTED PRODUCTS

vendor:opticammodel:i5 applicationscope:eqversion:2.21.1.128

Trust: 2.4

vendor:opticammodel:i5 systemscope:eqversion:1.5.2.11

Trust: 2.4

vendor:foscammodel:c2 applicationscope:eqversion:2.72.1.32

Trust: 1.8

vendor:foscammodel:c2 systemscope:eqversion:1.11.1.8

Trust: 1.8

vendor:foscammodel:c2 devices with systemscope:eqversion:1.11.1.8

Trust: 0.6

vendor:foscammodel:c2 devices with applicationscope:eqversion:2.72.1.32

Trust: 0.6

vendor:foscammodel:opticam i5 devices with systemscope:eqversion:1.5.2.11

Trust: 0.6

vendor:foscammodel:opticam i5 devices with applicationscope:eqversion:2.21.1.128

Trust: 0.6

sources: CNVD: CNVD-2019-04054 // JVNDB: JVNDB-2018-011650 // CNNVD: CNNVD-201811-142 // NVD: CVE-2018-19065

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-19065
value: HIGH

Trust: 1.0

NVD: CVE-2018-19065
value: HIGH

Trust: 0.8

CNVD: CNVD-2019-04054
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201811-142
value: MEDIUM

Trust: 0.6

VULHUB: VHN-129687
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-19065
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-04054
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-129687
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-19065
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-04054 // VULHUB: VHN-129687 // JVNDB: JVNDB-2018-011650 // CNNVD: CNNVD-201811-142 // NVD: CVE-2018-19065

PROBLEMTYPE DATA

problemtype:CWE-798

Trust: 1.9

sources: VULHUB: VHN-129687 // JVNDB: JVNDB-2018-011650 // NVD: CVE-2018-19065

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201811-142

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-201811-142

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-011650

PATCH

title:C2url:https://www.foscam.com/C2.html

Trust: 0.8

sources: JVNDB: JVNDB-2018-011650

EXTERNAL IDS

db:NVDid:CVE-2018-19065

Trust: 3.1

db:JVNDBid:JVNDB-2018-011650

Trust: 0.8

db:CNNVDid:CNNVD-201811-142

Trust: 0.7

db:CNVDid:CNVD-2019-04054

Trust: 0.6

db:VULHUBid:VHN-129687

Trust: 0.1

sources: CNVD: CNVD-2019-04054 // VULHUB: VHN-129687 // JVNDB: JVNDB-2018-011650 // CNNVD: CNNVD-201811-142 // NVD: CVE-2018-19065

REFERENCES

url:https://sintonen.fi/advisories/foscam-ip-camera-multiple-vulnerabilities.txt

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2018-19065

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-19065

Trust: 0.8

url:https://www.verkkokauppa.com/fi/product/52328/fcqxq/opticam-i5-hd-ip-kamera

Trust: 0.8

sources: CNVD: CNVD-2019-04054 // VULHUB: VHN-129687 // JVNDB: JVNDB-2018-011650 // CNNVD: CNNVD-201811-142 // NVD: CVE-2018-19065

SOURCES

db:CNVDid:CNVD-2019-04054
db:VULHUBid:VHN-129687
db:JVNDBid:JVNDB-2018-011650
db:CNNVDid:CNNVD-201811-142
db:NVDid:CVE-2018-19065

LAST UPDATE DATE

2024-11-23T22:12:13.012000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-04054date:2019-02-14T00:00:00
db:VULHUBid:VHN-129687date:2018-12-11T00:00:00
db:JVNDBid:JVNDB-2018-011650date:2019-01-18T00:00:00
db:CNNVDid:CNNVD-201811-142date:2018-11-08T00:00:00
db:NVDid:CVE-2018-19065date:2024-11-21T03:57:15.583

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-04054date:2019-02-14T00:00:00
db:VULHUBid:VHN-129687date:2018-11-07T00:00:00
db:JVNDBid:JVNDB-2018-011650date:2019-01-18T00:00:00
db:CNNVDid:CNNVD-201811-142date:2018-11-08T00:00:00
db:NVDid:CVE-2018-19065date:2018-11-07T18:29:01.180