Описание
In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration panel) is vulnerable to an OS system command injection as root.
Ссылки
- Third Party AdvisoryVDB Entry
- MitigationThird Party AdvisoryUS Government Resource
- Third Party AdvisoryVDB Entry
- MitigationThird Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 1.12.0.25 (исключая)
Одновременно
cpe:2.3:o:geutebrueck:g-cam\/efd-2251_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:geutebrueck:g-cam\/efd-2251:-:*:*:*:*:*:*:*
Конфигурация 2Версия до 1.12.0.25 (исключая)
Одновременно
cpe:2.3:o:geutebrueck:g-cam\/ewpc-2275_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:geutebrueck:g-cam\/ewpc-2275:-:*:*:*:*:*:*:*
EPSS
Процентиль: 81%
0.0154
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-78
CWE-78
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration panel) is vulnerable to an OS system command injection as root.
EPSS
Процентиль: 81%
0.0154
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-78
CWE-78