SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-19075

The firewall feature makes it easier for remote attackers to ascertain credentials and firewall rules because invalid credentials lead to error -2, whereas rule-based blocking leads to error -8.

MEDIUM 5.3EPSS 1.69%

Does this matter?

Lower severity and a low EPSS score (1.69%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The firewall feature makes it easier for remote attackers to ascertain credentials and firewall rules because invalid credentials lead to error -2, whereas rule-based blocking leads to error -8.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.69% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
opticam/i5 application firmware · opticam/i5 system firmware · foscam/c2 application firmware · foscam/c2 system firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.