9.8
CVE-2018-17879
- EPSS 2.14%
- Veröffentlicht 26.10.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 03:55:07
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scripts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Abus ≫ Tvip 10000 Firmware Version-
Abus ≫ Tvip 10001 Firmware Version-
Abus ≫ Tvip 10005 Firmware Version-
Abus ≫ Tvip 10005a Firmware Version-
Abus ≫ Tvip 10005b Firmware Version-
Abus ≫ Tvip 10050 Firmware Version-
Abus ≫ Tvip 10051 Firmware Version-
Abus ≫ Tvip 10055a Firmware Version-
Abus ≫ Tvip 10055b Firmware Version-
Abus ≫ Tvip 10500 Firmware Version-
Abus ≫ Tvip 10550 Firmware Version-
Abus ≫ Tvip 11000 Firmware Version-
Abus ≫ Tvip 11050 Firmware Version-
Abus ≫ Tvip 11500 Firmware Version-
Abus ≫ Tvip 11501 Firmware Version-
Abus ≫ Tvip 11502 Firmware Version-
Abus ≫ Tvip 11550 Firmware Version-
Abus ≫ Tvip 11551 Firmware Version-
Abus ≫ Tvip 11552 Firmware Version-
Abus ≫ Tvip 20000 Firmware Version-
Abus ≫ Tvip 20050 Firmware Version-
Abus ≫ Tvip 20500 Firmware Version-
Abus ≫ Tvip 20550 Firmware Version-
Abus ≫ Tvip 21000 Firmware Version-
Abus ≫ Tvip 21050 Firmware Version-
Abus ≫ Tvip 21500 Firmware Version-
Abus ≫ Tvip 21501 Firmware Version-
Abus ≫ Tvip 21502 Firmware Version-
Abus ≫ Tvip 21550 Firmware Version-
Abus ≫ Tvip 21551 Firmware Version-
Abus ≫ Tvip 21552 Firmware Version-
Abus ≫ Tvip 22500 Firmware Version-
Abus ≫ Tvip 31000 Firmware Version-
Abus ≫ Tvip 31001 Firmware Version-
Abus ≫ Tvip 31050 Firmware Version-
Abus ≫ Tvip 31500 Firmware Version-
Abus ≫ Tvip 31501 Firmware Version-
Abus ≫ Tvip 31550 Firmware Version-
Abus ≫ Tvip 31551 Firmware Version-
Abus ≫ Tvip 32500 Firmware Version-
Abus ≫ Tvip 51500 Firmware Version-
Abus ≫ Tvip 51550 Firmware Version-
Abus ≫ Tvip 71500 Firmware Version-
Abus ≫ Tvip 71501 Firmware Version-
Abus ≫ Tvip 71550 Firmware Version-
Abus ≫ Tvip 71551 Firmware Version-
Abus ≫ Tvip 72500 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.14% | 0.826 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.