ZeroHour

CVE-2018-12666

PoC
CVSS 3.0
9.8 critical
EPSS
2%p78
Published
()
Modified
Description

SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, which allow remote attackers to bypass authentication and gain administrator access by setting the authLevel cookie to 255.

Vendors
sv3c
Products
h.264 poe ip camera firmware
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.