ZeroHour

CVE-2018-12674

PoC
CVSS 3.0
5.7 medium
EPSS
<1%p45
Published
()
Modified
Description

The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and password within the cookies of a session. If an attacker gained access to these session cookies, it would be possible to gain access to the username and password of the logged-in account.

Vendors
sv3c
Products
h.264 poe ip camera firmware
Weakness
CWE-319
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.