VulnerabilityModified
CVE-2021-26627
Real-time image information exposure is caused by insufficient authentication for activated RTSP port.
HIGH 7.5EPSS 1.43%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attackers to send the RTSP requests using ffplay command and lead to leakage a live image.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.43% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-287
- Affected
- qcp/qcp200w firmware
- Source
- vuln@krcert.or.kr
References
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66663Third Party Advisory
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66663Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.