CVE-2014-8384
The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configuration, reboot the device, change the device name, and have other…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configuration, reboot the device, change the device name, and have other unspecified impact via a crafted request.
- CVSS 2.0
- 9.4 HIGHAV:N/AC:L/Au:N/C:N/I:C/A:C
- EPSS
- 3.21% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- infocus/in3128hd firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/131661/InFocus-IN3128HD-Projector-Missing-Authentication.htmlExploit
- http://seclists.org/fulldisclosure/2015/Apr/88Exploit
- http://www.coresecurity.com/advisories/infocus-in3128hd-projector-multiple-vulnerabilitiesExploit, Vendor Advisory
- http://packetstormsecurity.com/files/131661/InFocus-IN3128HD-Projector-Missing-Authentication.htmlExploit
- http://seclists.org/fulldisclosure/2015/Apr/88Exploit
- http://www.coresecurity.com/advisories/infocus-in3128hd-projector-multiple-vulnerabilitiesExploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.