René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

121 lines
3.7 KiB
JSON

{
"id": "CVE-2018-6407",
"sourceIdentifier": "cve@mitre.org",
"published": "2018-01-30T21:29:00.447",
"lastModified": "2018-02-27T16:12:09.740",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to /hy-cgi/devices.cgi?cmd=searchlandevice. The crash completely freezes the device."
},
{
"lang": "es",
"value": "Se ha descubierto un problema en dispositivos Conceptronic CIPCAMPTIWL V3 0.61.30.21. Un atacante no autenticado puede provocar el cierre inesperado de un dispositivo mediante el env\u00edo de una petici\u00f3n POST con un gran tama\u00f1o de cuerpo a /hy-cgi/devices.cgi?cmd=searchlandevice. El cierre inesperado bloquea completamente el dispositivo."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "COMPLETE",
"baseScore": 7.8
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:conceptronic:cipcamptiwl_firmware:00.30.01.0047p3:*:*:*:*:*:*:*",
"matchCriteriaId": "8C4186D5-370B-4314-9A0E-CE33F555E06C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:conceptronic:cipcamptiwl_web_firmware:0.61.30.21:*:*:*:*:*:*:*",
"matchCriteriaId": "1CDB1816-B9A6-44D4-8B2F-0CB2B968C2B4"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:conceptronic:cipcamptiwl:3:*:*:*:*:*:*:*",
"matchCriteriaId": "BD27F14B-17BC-4499-883F-EF75E13CCA33"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/dreadlocked/ConceptronicIPCam_MultipleVulnerabilities/",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
}
]
}