Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-58rw-8pf6-2mgq

Опубликовано: 17 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.

EPSS

Процентиль: 99%
0.82393
Высокий

9.1 Critical

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 9.1
nvd
больше 1 года назад

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.

CVSS3: 9.1
fstec
больше 1 года назад

Уязвимость микропрограммного обеспечения веб-камер PTZOptics PT30X-SDI/NDI, связанная с неправильной аутентификацией, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.82393
Высокий

9.1 Critical

CVSS3

Дефекты

CWE-287
CWE-306