ID

VAR-201811-0823


CVE

CVE-2018-19066


TITLE

Foscam C2 Device and Opticam i5 Vulnerabilities related to the use of hard-coded credentials on devices

Trust: 0.8

sources: JVNDB: JVNDB-2018-011651

DESCRIPTION

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The exported device configuration is encrypted with the hardcoded Pxift* password in some cases. Foscam C2 Device and Opticam i5 The device contains a vulnerability related to the use of hard-coded credentials.Information may be obtained. Both Foscam C2 and Opticami 5 are network camera products from China Foscom (FOSCAM). An information disclosure vulnerability exists in the FoscamC2 and Opticami5 devices that originated from the configuration backup file using a hard-coded password (Pxift*) that an attacker could use to control the device

Trust: 2.25

sources: NVD: CVE-2018-19066 // JVNDB: JVNDB-2018-011651 // CNVD: CNVD-2019-04053 // VULHUB: VHN-129688

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-04053

AFFECTED PRODUCTS

vendor:opticammodel:i5 applicationscope:eqversion:2.21.1.128

Trust: 2.4

vendor:opticammodel:i5 systemscope:eqversion:1.5.2.11

Trust: 2.4

vendor:foscammodel:c2 applicationscope:eqversion:2.72.1.32

Trust: 1.8

vendor:foscammodel:c2 systemscope:eqversion:1.11.1.8

Trust: 1.8

vendor:foscammodel:c2 devices with systemscope:eqversion:1.11.1.8

Trust: 0.6

vendor:foscammodel:c2 devices with applicationscope:eqversion:2.72.1.32

Trust: 0.6

vendor:foscammodel:opticam i5 devices with systemscope:eqversion:1.5.2.11

Trust: 0.6

vendor:foscammodel:opticam i5 devices with applicationscope:eqversion:2.21.1.128

Trust: 0.6

sources: CNVD: CNVD-2019-04053 // JVNDB: JVNDB-2018-011651 // CNNVD: CNNVD-201811-143 // NVD: CVE-2018-19066

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-19066
value: HIGH

Trust: 1.0

NVD: CVE-2018-19066
value: HIGH

Trust: 0.8

CNVD: CNVD-2019-04053
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201811-143
value: MEDIUM

Trust: 0.6

VULHUB: VHN-129688
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-19066
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-04053
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-129688
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-19066
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-04053 // VULHUB: VHN-129688 // JVNDB: JVNDB-2018-011651 // CNNVD: CNNVD-201811-143 // NVD: CVE-2018-19066

PROBLEMTYPE DATA

problemtype:CWE-798

Trust: 1.9

sources: VULHUB: VHN-129688 // JVNDB: JVNDB-2018-011651 // NVD: CVE-2018-19066

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201811-143

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-201811-143

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-011651

PATCH

title:C2url:https://www.foscam.com/C2.html

Trust: 0.8

sources: JVNDB: JVNDB-2018-011651

EXTERNAL IDS

db:NVDid:CVE-2018-19066

Trust: 3.1

db:JVNDBid:JVNDB-2018-011651

Trust: 0.8

db:CNNVDid:CNNVD-201811-143

Trust: 0.7

db:CNVDid:CNVD-2019-04053

Trust: 0.6

db:VULHUBid:VHN-129688

Trust: 0.1

sources: CNVD: CNVD-2019-04053 // VULHUB: VHN-129688 // JVNDB: JVNDB-2018-011651 // CNNVD: CNNVD-201811-143 // NVD: CVE-2018-19066

REFERENCES

url:https://sintonen.fi/advisories/foscam-ip-camera-multiple-vulnerabilities.txt

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2018-19066

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-19066

Trust: 0.8

url:https://www.verkkokauppa.com/fi/product/52328/fcqxq/opticam-i5-hd-ip-kamera

Trust: 0.8

sources: CNVD: CNVD-2019-04053 // VULHUB: VHN-129688 // JVNDB: JVNDB-2018-011651 // CNNVD: CNNVD-201811-143 // NVD: CVE-2018-19066

SOURCES

db:CNVDid:CNVD-2019-04053
db:VULHUBid:VHN-129688
db:JVNDBid:JVNDB-2018-011651
db:CNNVDid:CNNVD-201811-143
db:NVDid:CVE-2018-19066

LAST UPDATE DATE

2024-11-23T22:17:15.338000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-04053date:2019-02-14T00:00:00
db:VULHUBid:VHN-129688date:2018-12-11T00:00:00
db:JVNDBid:JVNDB-2018-011651date:2019-01-18T00:00:00
db:CNNVDid:CNNVD-201811-143date:2018-11-08T00:00:00
db:NVDid:CVE-2018-19066date:2024-11-21T03:57:15.730

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-04053date:2019-02-14T00:00:00
db:VULHUBid:VHN-129688date:2018-11-07T00:00:00
db:JVNDBid:JVNDB-2018-011651date:2019-01-18T00:00:00
db:CNNVDid:CNNVD-201811-143date:2018-11-08T00:00:00
db:NVDid:CVE-2018-19066date:2018-11-07T18:29:01.570