9

CVE-2019-10958

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to network configuration to supply system commands to the server, leading to remote code execution as root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GeutebrueckG-code Eec-2400 Firmware Version <= 1.12.0.25
   GeutebrueckG-code Eec-2400 Version-
GeutebrueckG-cam Ebc-2110 Firmware Version <= 1.12.0.25
   GeutebrueckG-cam Ebc-2110 Version-
GeutebrueckG-cam Ebc-2111 Firmware Version <= 1.12.0.25
   GeutebrueckG-cam Ebc-2111 Version-
GeutebrueckG-cam Efd-2240 Firmware Version <= 1.12.0.25
   GeutebrueckG-cam Efd-2240 Version-
GeutebrueckG-cam Efd-2241 Firmware Version <= 1.12.0.25
   GeutebrueckG-cam Efd-2241 Version-
GeutebrueckG-cam Efd-2250 Firmware Version <= 1.12.0.25
   GeutebrueckG-cam Efd-2250 Version-
GeutebrueckG-cam Ethc-2230 Firmware Version <= 1.12.0.25
   GeutebrueckG-cam Ethc-2230 Version-
GeutebrueckG-cam Ethc-2240 Firmware Version <= 1.12.0.25
   GeutebrueckG-cam Ethc-2240 Version-
GeutebrueckG-cam Ethc-2239 Firmware Version <= 1.12.0.25
   GeutebrueckG-cam Ethc-2239 Version-
GeutebrueckG-cam Ethc-2249 Firmware Version <= 1.12.0.25
   GeutebrueckG-cam Ethc-2249 Version-
GeutebrueckG-cam Ewpc-2270 Firmware Version <= 1.12.0.25
   GeutebrueckG-cam Ewpc-2270 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.76% 0.725
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.