CVE-2018-19007
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration panel) is vulnerable to an OS system command injection as root.
Affected (2)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.12.0.25 |
| Running on/with | Platform Versions |
|---|---|
Geutebrueck G Cam/efd 2251 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.12.0.25 |
| Running on/with | Platform Versions |
|---|---|
Geutebrueck G Cam/ewpc 2275 | All versions |
References (4)
Source: ics-cert@hq.dhs.gov
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource
Timeline
No history available yet.