CVE-2019-10958
Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to network configuration to supply system commands to the server, leading to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.27%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to network configuration to supply system commands to the server, leading to remote code execution as root.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.27% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- geutebrueck/g-code eec-2400 firmware · geutebrueck/g-cam ebc-2110 firmware · geutebrueck/g-cam ebc-2111 firmware · geutebrueck/g-cam efd-2240 firmware · geutebrueck/g-cam efd-2241 firmware · geutebrueck/g-cam efd-2250 firmware · geutebrueck/g-cam ethc-2230 firmware · geutebrueck/g-cam ethc-2240 firmware · geutebrueck/g-cam ethc-2239 firmware · geutebrueck/g-cam ethc-2249 firmware · geutebrueck/g-cam ewpc-2270 firmware
- Source
- ics-cert@hq.dhs.gov
References
- https://www.us-cert.gov/ics/advisories/ICSA-19-155-03Third Party Advisory, US Government Resource
- https://www.us-cert.gov/ics/advisories/ICSA-19-155-03Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.