漏洞标题
N/A
漏洞描述信息
在Foscam Camera C1 Lite V3和C1 V3的固件2.82.2.33之前,以及更早版本中,fi9800p v3,fi9803p v4,fi9851p v3和fi9853ep v2的固件2.84.2.33之前,fi9816p v3,fi9821ep v2,fi9821p v3,fi9826p v3和fi9831p v3的固件2.81.2.33之前,以及更早版本中的C1,C1 v2,C1 Lite和C1 Lite v2的固件2.52.2.47之前,fi9800p,fi9800p v2,fi9803p v2,fi9803p v3和fi9851p v2的固件2.54.2.47之前,fi9815p,fi9815p v2,fi9816p v2和fi9816p v2的固件2.51.2.47之前,r2和r4的固件2.71.1.59之前,c2和fi9961ep的固件2.72.1.59之前,fi9900ep,fi9900p和fi9901ep的固件2.74.1.59之前,fi9928p的固件2.74.1.58之前,fi9803ep和fi9853ep的固件2.22.2.31之前,fi9803p和fi9851p的固件2.24.2.31之前,fi9821p v2,fi9826p v2,fi9831p v2和fi9821ep的固件2.21.2.31之前,fi9821w v2,fi9831w,fi9826w,fi9821p,fi9831p和fi9826p的固件2.11.1.120之前,fi9818w v2的固件2.13.2.120之前,fi9805w,fi9804w,fi9804p,fi9805e和fi9805p的固件2.14.1.120之前,fi9828p和fi9828w的固件2.13.1.120之前,以及fi9828p v2的固件2.11.1.133之前,允许远程授权用户可以通过在ntpServer参数中带有的';'执行任意命令。请注意,此问题存在,因为CVE-2017-2849的 incomplete 修复。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
The setSystemTime function in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1 Lite V2 2.52.2.47 and earlier, FI9800P, FI9800P V2, FI9803P V2, FI9803P V3, and FI9851P V2 2.54.2.47 and earlier, FI9815P, FI9815P V2, FI9816P, and FI9816P V2, 2.51.2.47 and earlier, R2 and R4 2.71.1.59 and earlier, C2 and FI9961EP 2.72.1.59 and earlier, FI9900EP, FI9900P, and FI9901EP 2.74.1.59 and earlier, FI9928P 2.74.1.58 and earlier, FI9803EP and FI9853EP 2.22.2.31 and earlier, FI9803P and FI9851P 2.24.2.31 and earlier, FI9821P V2, FI9826P V2, FI9831P V2, and FI9821EP 2.21.2.31 and earlier, FI9821W V2, FI9831W, FI9826W, FI9821P, FI9831P, and FI9826P 2.11.1.120 and earlier, FI9818W V2 2.13.2.120 and earlier, FI9805W, FI9804W, FI9804P, FI9805E, and FI9805P 2.14.1.120 and earlier, FI9828P, and FI9828W 2.13.1.120 and earlier, and FI9828P V2 2.11.1.133 and earlier allows remote authenticated users to execute arbitrary commands via a ';' in the ntpServer argument. NOTE: this issue exists because of an incomplete fix for CVE-2017-2849.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
多款Foscam产品安全漏洞
漏洞描述信息
Foscam Cameras C1 Lite V3等都是中国福斯康姆(FOSCAM)公司的网络摄像机产品。 多款Foscam Cameras产品中的‘setSystemTime’函数存在安全漏洞。远程攻击者可借助ntpServer参数中的‘;’利用该漏洞执行任意命令。以下产品和版本受到影响:使用2.82.2.33及之前版本固件的Foscam Cameras C1 Lite V3;使用2.82.2.33及之前版本固件的Foscam Cameras C1 V3;使用2.84.2.33及之前版本固件的Fosca
CVSS信息
N/A
漏洞类别
授权问题