VulnerabilityModified
CVE-2017-8225
An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.
CRITICAL 9.8EPSS 35.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 35.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 35.36% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- wificam/wireless ip camera \(p2p\) firmware
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2017/Mar/23Exploit, Mailing List, Third Party Advisory
- https://pierrekim.github.io/blog/2017-03-08-camera-goahead-0day.html#pre-auth-info-leak-goaheadExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2017/Mar/23Exploit, Mailing List, Third Party Advisory
- https://pierrekim.github.io/blog/2017-03-08-camera-goahead-0day.html#pre-auth-info-leak-goaheadExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.