ZeroHour

CVE-2019-14699

CVSS 3.0
9.8 critical
EPSS
6%p93
Published
()
Modified
Description

An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filename parameter for remote code execution as root. This occurs in the Mainproc executable file, which can be run from the HTTPD web server.

Vendors
microdigital
Products
mdc-n4090 firmware, mdc-n4090w firmware, mdc-n2190v firmware
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.