7.5
CVE-2018-17240
- EPSS 3.68%
- Veröffentlicht 10.06.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 03:54:08
- CVE-Watchlists
- Unerledigt
There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netwavepr ≫ Indoor Ip Camera Firmware Version-
Netwavepr ≫ Outdoor Ip Camera Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.68% | 0.886 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-401 Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
https://github.com/BBge/CVE-2018-17240
https://github.com/BBge/CVE-2018-17240/blob/main/exploit.py
https://www.bbge.org/file/exploit.py