Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m7v9-w9c3-mw2g

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core system files including those used for authentication (such as passwd and shadow). This can be abused to take full root level control of the device.

On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core system files including those used for authentication (such as passwd and shadow). This can be abused to take full root level control of the device.

EPSS

Процентиль: 80%
0.01334
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
около 8 лет назад

On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core system files including those used for authentication (such as passwd and shadow). This can be abused to take full root level control of the device.

CVSS3: 9.8
fstec
больше 8 лет назад

Уязвимость FTP-сервера микропрограммного обеспечения IP-камеры Jooan A5 IP Camera, позволяющая нурушителю получить доступ к устройству с привилегиями root

EPSS

Процентиль: 80%
0.01334
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287