CVE-2018-12666
Summary
| CVE | CVE-2018-12666 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-19 22:29:00 UTC |
| Updated | 2019-01-28 13:46:00 UTC |
| Description | SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, which allow remote attackers to bypass authentication and gain administrator access by setting the authLevel cookie to 255. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Sv3c | H.264 Poe Ip Camera Firmware | v2.3.4.2103-s50-ntd-b20170508b | All | All | All |
| Operating System | Sv3c | H.264 Poe Ip Camera Firmware | v2.3.4.2103-s50-ntd-b20170823b | All | All | All |
| Operating System | Sv3c | H.264 Poe Ip Camera Firmware | v2.3.4.2103-s50-ntd-b20170508b | All | All | All |
| Operating System | Sv3c | H.264 Poe Ip Camera Firmware | v2.3.4.2103-s50-ntd-b20170823b | All | All | All |
| Hardware | Sv3c | Sv-b01poe-1080p-l | - | All | All | All |
| Hardware | Sv3c | Sv-b01poe-1080p-l | - | All | All | All |
| Hardware | Sv3c | Sv-b11vpoe-1080p-l | - | All | All | All |
| Hardware | Sv3c | Sv-b11vpoe-1080p-l | - | All | All | All |
| Hardware | Sv3c | Sv-d02poe-1080p-l | - | All | All | All |
| Hardware | Sv3c | Sv-d02poe-1080p-l | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SV3C L-Series HD Camera – Multiple Vulnerabilities | MISC | www.bishopfox.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.