9.8

CVE-2018-12666

Exploit
SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, which allow remote attackers to bypass authentication and gain administrator access by setting the authLevel cookie to 255.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sv3cH.264 Poe Ip Camera Firmware Versionv2.3.4.2103-s50-ntd-b20170508b
   Sv3cSv-b01poe-1080p-l Version-
   Sv3cSv-b11vpoe-1080p-l Version-
   Sv3cSv-d02poe-1080p-l Version-
Sv3cH.264 Poe Ip Camera Firmware Versionv2.3.4.2103-s50-ntd-b20170823b
   Sv3cSv-b01poe-1080p-l Version-
   Sv3cSv-b11vpoe-1080p-l Version-
   Sv3cSv-d02poe-1080p-l Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.1% 0.761
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.