An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including all password sets set within the camera. This information can then be used to gain access to the web interface.
References
Link | Resource |
---|---|
https://www.bishopfox.com/news/2018/10/sv3c-l-series-hd-camera-multiple-vulnerabilities/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Information
Published : 2018-10-19 15:29
Updated : 2019-01-11 08:41
NVD link : CVE-2018-12671
Mitre link : CVE-2018-12671
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
sv3c
- sv-b01poe-1080p-l
- sv-d02poe-1080p-l
- h.264_poe_ip_camera_firmware
- sv-b11vpoe-1080p-l