7.5

CVE-2018-16946

Exploit

LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.

Data is provided by the National Vulnerability Database (NVD)
LgLnb5110 Firmware Version >= 1310250 <= 1508190
   LgLnb5110 Version-
LgLnb5320 Firmware Version >= 1310250 <= 1508190
   LgLnb5320 Version-
LgLnb5320r Firmware Version >= 1310250 <= 1508190
   LgLnb5320r Version-
LgLnb7210 Firmware Version >= 1310250 <= 1508190
   LgLnb7210 Version-
LgLnd3230r Firmware Version >= 1310250 <= 1508190
   LgLnd3230r Version-
LgLnd5110 Firmware Version >= 1310250 <= 1508190
   LgLnd5110 Version-
LgLnd5110r Firmware Version >= 1310250 <= 1508190
   LgLnd5110r Version-
LgLnd5220r Firmware Version >= 1310250 <= 1508190
   LgLnd5220r Version-
LgLnd7210 Firmware Version >= 1310250 <= 1508190
   LgLnd7210 Version-
LgLnd7210r Firmware Version >= 1310250 <= 1508190
   LgLnd7210r Version-
LgLnu3230r Firmware Version >= 1310250 <= 1508190
   LgLnu3230r Version-
LgLnu5110r Firmware Version >= 1310250 <= 1508190
   LgLnu5110r Version-
LgLnu5320r Firmware Version >= 1310250 <= 1508190
   LgLnu5320r Version-
LgLnu7210r Firmware Version >= 1310250 <= 1508190
   LgLnu7210r Version-
LgLnv5110r Firmware Version >= 1310250 <= 1508190
   LgLnv5110r Version-
LgLnv5320r Firmware Version >= 1310250 <= 1508190
   LgLnv5320r Version-
LgLnv7210 Firmware Version >= 1310250 <= 1508190
   LgLnv7210 Version-
LgLnv7210r Firmware Version >= 1310250 <= 1508190
   LgLnv7210r Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 11.52% 0.933
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.