Описание
Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which allow remote attackers to obtain sensitive information (user names, passwords, and configurations) via a get action.
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.6.16c1 (включая)
Одновременно
cpe:2.3:o:brickcom:100ap_device_firmware:*:*:*:*:*:*:*:*
Одно из
cpe:2.3:h:brickcom:fb-100ap:-:*:*:*:*:*:*:*
cpe:2.3:h:brickcom:md-100ap:-:*:*:*:*:*:*:*
cpe:2.3:h:brickcom:ob-100ae:-:*:*:*:*:*:*:*
cpe:2.3:h:brickcom:osd-040e:-:*:*:*:*:*:*:*
cpe:2.3:h:brickcom:wcb-100ap:-:*:*:*:*:*:*:*
cpe:2.3:h:brickcom:wfb-100ap:-:*:*:*:*:*:*:*
EPSS
Процентиль: 55%
0.00319
Низкий
7.8 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
больше 3 лет назад
Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which allow remote attackers to obtain sensitive information (user names, passwords, and configurations) via a get action.
EPSS
Процентиль: 55%
0.00319
Низкий
7.8 High
CVSS2
Дефекты
CWE-264