9.8
CVE-2015-6970
- EPSS 9.43%
- Veröffentlicht 18.02.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 02:35:57
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Boschsecurity ≫ Nbn-498 Dinion2x Day/night Ip Cameras Firmware Version4.54.0026
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.43% | 0.925 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-91 XML Injection (aka Blind XPath Injection)
The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.