CVE-2019-14699
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filename parameter for remote code execution as root. This occurs in the Mainproc executable file, which can be run from the HTTPD web server.
Affected (3)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6400.0.8.5 |
| Running on/with | Platform Versions |
|---|---|
Microdigital Mdc N4090 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6400.0.8.5 |
| Running on/with | Platform Versions |
|---|---|
Microdigital Mdc N4090w | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6400.0.8.5 |
| Running on/with | Platform Versions |
|---|---|
Microdigital Mdc N2190v | All versions |
References (6)
Timeline
No history available yet.