9.8

CVE-2019-14709

A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrodigitalMdc-n4090 Firmware Version <= 6400.0.8.5
   MicrodigitalMdc-n4090 Version-
MicrodigitalMdc-n4090w Firmware Version <= 6400.0.8.5
   MicrodigitalMdc-n4090w Version-
MicrodigitalMdc-n2190v Firmware Version <= 6400.0.8.5
   MicrodigitalMdc-n2190v Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.582
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.