CVE-2019-6973
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds.
Affected (1)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.8.0 |
| Running on/with | Platform Versions |
|---|---|
Sricam Nvs001 | All versions |
Sricam Sh016 | All versions |
Sricam Sh024 | All versions |
Sricam Sh026 | All versions |
Sricam Sh027 | All versions |
Sricam Sp007 | All versions |
Sricam Sp008 | All versions |
Sricam Sp009 | All versions |
Sricam Sp012 | All versions |
Sricam Sp015 | All versions |
Sricam Sp017 | All versions |
Sricam Sp018 | All versions |
Sricam Sp019 | All versions |
Sricam Sp020 | All versions |
Sricam Sp023 | All versions |
References (6)
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Timeline
No history available yet.