mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-29 01:31:20 +00:00
551 lines
15 KiB
JSON
551 lines
15 KiB
JSON
{
|
|
"id": "CVE-2023-6118",
|
|
"sourceIdentifier": "iletisim@usom.gov.tr",
|
|
"published": "2023-11-23T15:15:10.583",
|
|
"lastModified": "2023-11-30T21:03:09.543",
|
|
"vulnStatus": "Analyzed",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Path Traversal: '/../filedir' vulnerability in Neutron IP Camera allows Absolute Path Traversal.This issue affects IP Camera: before b1130.1.0.1.\n\n"
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": ": Path Traversal: la vulnerabilidad '/../filedir' en Neutron IP Camera permite un Absolute Path Traversal. Este problema afecta a IP Camera: anterior a b1130.1.0.1."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "iletisim@usom.gov.tr",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "HIGH",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 7.5,
|
|
"baseSeverity": "HIGH"
|
|
},
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 3.6
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-22"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"source": "iletisim@usom.gov.tr",
|
|
"type": "Secondary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-25"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:neu-ipb210-28_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "E9E17F5B-4BCD-4B73-B75E-E2DF2A881568"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:neu-ipb210-28:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "02E29DB6-831D-4D32-9977-377505D7154E"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:ntl-pt-06wod-3mp_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "DD8EB50E-AB61-4164-A64B-767D88C11178"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:ntl-pt-06wod-3mp:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "CC3FB86D-1E37-4DB8-8CC8-B3EF9D222118"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:neu-ipb410-28_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "B08ECB23-FD9F-4349-BC23-C60DCB1C492C"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:neu-ipb410-28:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "7A10018A-43D9-4D2E-A9AC-550C5D7D6E13"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:ntl-bc-01w_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "8CE3F378-9281-42E3-BB9C-EE65F625C0D6"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:ntl-bc-01w:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4D2D9338-5E7C-4519-BDE1-6B827D2CB55F"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:neu-ipbm211_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "BA541A95-FAF0-4E97-B795-E9F295EB8781"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:neu-ipbm211:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "8C0D0159-2A14-421E-894F-7E3A5159274E"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:ntl-pt-09-wos-3mp_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "9C7F2C36-C14D-4DFA-8E32-BBCA1B9F7020"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:ntl-pt-09-wos-3mp:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D14FDBEB-6F79-4788-8720-BFFEEDA2E05D"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:neu-ipbm411_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "79C1B425-92A1-40F2-B855-D462102E50B6"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:neu-ipbm411:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5E8F3B75-97FE-4456-9D37-327283CAEEF1"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:ntl-pt-10-4gwos-3mp_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "24AE955A-C6FC-4000-812B-84438C0F4832"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:ntl-pt-10-4gwos-3mp:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "24CF1DB2-9D3E-40EE-A640-BD70EF9C67C0"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:ipc2224-sr3-npf-36_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "C0A6911A-BC7D-426F-A0A1-DCE8DFB6E472"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:ipc2224-sr3-npf-36:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "597EAF61-E256-4E2B-9E3B-EA8CDCFE2623"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:ipc2624-sr3-npf-36_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "1C49227E-A9B1-4F80-BA1A-8F1FDF257A46"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:ipc2624-sr3-npf-36:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "51A15202-CCFD-46C8-86E2-CCD68EADAAC2"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:ntl-bc-03-snm_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "BC42EE6D-2F7B-4B95-99AA-7EAB593E795E"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:ntl-bc-03-snm:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "99011562-59ED-45D1-AFFE-D19BD1B74DB8"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:ntl-bc-03-snp_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "786836E4-7A57-464E-94B9-1F6F4F8C159F"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:ntl-bc-03-snp:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E2EA5604-EF9F-4FF7-AA8D-38C626DB1B3B"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:neu-ipd220-28_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "27FD6535-5A60-4AFB-BB3C-8A7AA6A88CB6"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:neu-ipd220-28:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "113B05D6-6263-4379-80EA-40E5B95468A4"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:ntl-bc01-m_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "B81FB586-9DE5-4108-A213-6C969E8BB8E9"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:ntl-bc01-m:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "EA533B42-E832-4817-BC68-530DBA778EED"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:neu-ipdm221_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "BE3208EB-EC1B-4CC2-8044-52F003719112"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:neu-ipdm221:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "8749B6F5-5E72-41C5-93A5-024E61C2FECB"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:neu-ipdm421_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "6D28A715-523B-4B4D-82EA-57D99BB39245"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:neu-ipdm421:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "268747DD-EE4A-4379-B8D7-792CDFF0FE47"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:neutron:ntl-ip05-3mp_firmware:*:*:*:*:*:*:*:*",
|
|
"versionEndExcluding": "b1130.1.0.1",
|
|
"matchCriteriaId": "1D10738A-B998-48F6-9DE7-B38D011986E7"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:neutron:ntl-ip05-3mp:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2DEE39BB-5792-4807-908C-5CDB086F5A4F"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://www.usom.gov.tr/bildirim/tr-23-0658",
|
|
"source": "iletisim@usom.gov.tr",
|
|
"tags": [
|
|
"Third Party Advisory"
|
|
]
|
|
}
|
|
]
|
|
} |