Vulnerability CVE-2018-13115


Published: 2018-10-22

Description:
Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream. The RTSP server on port 7070 accepts the command STOP to stop streaming, and the command SETSSID to disconnect a user.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.4/10
4.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
Keruigroup -> Ypc99 firmware 

 References:
https://utkusen.com/blog/multiple-vulnerabilities-on-kerui-endoscope-camera.html

Copyright 2024, cxsecurity.com

 

Back to Top