← Back

CVE-2018-19076

nvd nist
Published: Nov 7, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The FTP and RTSP services make it easier for attackers to conduct brute-force authentication attacks, because failed-authentication limits apply only to HTTP (not FTP or RTSP).

Affected (4)

2 products
I5 Application Firmware
I5 System Firmware
2 products
C2 Application Firmware
C2 System Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.21.1.128
Version 1.5.2.11
Running on/withPlatform Versions
Opticam
I5
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.72.1.32
Version 1.11.1.8
Running on/withPlatform Versions
Foscam
C2
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.