ZeroHour

CVE-2018-16546

CVSS 3.0
5.9 medium
EPSS
1%p61
Published
()
Modified
Description

Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation, as demonstrated by Amcrest_IPC-HX1X3X-LEXUS_Eng_N_AMCREST_V2.420.AC01.3.R.20180206.

Vendors
amcrest
Products
amcrest ipc-hx1x3x-lexus eng n amcrest
Weakness
CWE-798
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.