9
CVE-2018-0663
- EPSS 0.61%
- Published 07.09.2018 14:29:03
- Last modified 21.11.2024 03:38:41
- Source vultures@jpcert.or.jp
- Teams watchlist Login
- Open Login
Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) use hardcoded credentials which may allow an remote authenticated attacker to execute arbitrary OS commands on the device via unspecified vector.
Data is provided by the National Vulnerability Database (NVD)
Iodata ≫ Ts-wrlp Firmware Version <= 1.09.04
Iodata ≫ Ts-wrlp/e Firmware Version <= 1.09.04
Iodata ≫ Ts-wrla Firmware Version <= 1.09.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.61% | 0.689 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.