6.4

CVE-2014-3895

The I-O DATA TS-WLCAM camera with firmware 1.06 and earlier, TS-WLCAM/V camera with firmware 1.06 and earlier, TS-WPTCAM camera with firmware 1.08 and earlier, TS-PTCAM camera with firmware 1.08 and earlier, TS-PTCAM/POE camera with firmware 1.08 and earlier, and TS-WLC2 camera with firmware 1.02 and earlier allow remote attackers to bypass authentication, and consequently obtain sensitive credential and configuration data, via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
IodataTs-wptcam Camera Firmware Version <= 1.0.8
IodataTs-wptcam Camera Version-
IodataTs-wlcam Camera Firmware Version <= 1.06
IodataTs-wlcam Camera Version-
IodataTs-wlc2 Camera Firmware Version <= 1.02
IodataTs-wlc2 Camera Version-
IodataTs-ptcam Camera Firmware Version <= 1.08
IodataTs-ptcam Camera Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.3% 0.506
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.