VulnerabilityModified
CVE-2018-17879
The CGI scripts allow remote attackers to execute code via system() as root.
CRITICAL 9.8EPSS 21.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scripts.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 21.85% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- abus/tvip 10000 firmware · abus/tvip 10001 firmware · abus/tvip 10005 firmware · abus/tvip 10005a firmware · abus/tvip 10005b firmware · abus/tvip 10050 firmware · abus/tvip 10051 firmware · abus/tvip 10055a firmware · abus/tvip 10055b firmware · abus/tvip 10500 firmware · abus/tvip 10550 firmware · abus/tvip 11000 firmware · abus/tvip 11050 firmware · abus/tvip 11500 firmware · abus/tvip 11501 firmware · abus/tvip 11502 firmware · abus/tvip 11550 firmware · abus/tvip 11551 firmware · abus/tvip 11552 firmware · abus/tvip 20000 firmware · +27 more
- Source
- cve@mitre.org
References
- https://sec.maride.cc/posts/abus/#cve-2018-17879Exploit, Third Party Advisory
- https://www.ccc.de/en/updates/2019/update-nicht-verfugbar-hersteller-nicht-zu-erreichenThird Party Advisory
- https://sec.maride.cc/posts/abus/#cve-2018-17879Exploit, Third Party Advisory
- https://www.ccc.de/en/updates/2019/update-nicht-verfugbar-hersteller-nicht-zu-erreichenThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.