{"api_version":"1","generated_at":"2026-07-23T05:02:14+00:00","cve":"CVE-2017-3185","urls":{"html":"https://cve.report/CVE-2017-3185","api":"https://cve.report/api/cve/CVE-2017-3185.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-3185","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-3185"},"summary":{"title":"CVE-2017-3185","description":"ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.","state":"PUBLISHED","assigner":"certcc","published_at":"2017-12-16 02:29:10","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-598","CWE-200","CWE-598 CWE-598: Information Exposure Through Query Strings in GET Request"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://twitter.com/Hfuhs/status/839252357221330944","name":"https://twitter.com/Hfuhs/status/839252357221330944","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Press/Media Coverage","Third Party Advisory"],"title":"JavaScript is not available.","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/96720/info","name":"http://www.securityfocus.com/bid/96720/info","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"ACTi Cameras Models Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://twitter.com/hack3rsca/status/839599437907386368","name":"https://twitter.com/hack3rsca/status/839599437907386368","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Press/Media Coverage","Third Party Advisory"],"title":"Twitter / Konto zawieszone","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.kb.cert.org/vuls/id/355151","name":"https://www.kb.cert.org/vuls/id/355151","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Vulnerability Note VU#355151 - ACTi cameras models from the D, B, I, and E series contain multiple security vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/96720","name":"BID:96720","refsource":"MITRE","tags":[],"title":"ACTi Cameras Models Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-3185","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-3185","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"ACTi Corporation","product":"ACTi D, B, I, and E series cameras","version":"affected A1D-500-V6.11.31-AC","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"3185","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"acti","cpe5":"camera_firmware","cpe6":"a1d-500-v6.11.31-ac","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"3185","cve":"CVE-2017-3185","epss":"0.017120000","percentile":"0.825530000","score_date":"2026-05-18","updated_at":"2026-05-19 00:10:21"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T14:16:28.235Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://twitter.com/hack3rsca/status/839599437907386368"},{"name":"96720","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/96720/info"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://twitter.com/Hfuhs/status/839252357221330944"},{"name":"VU#355151","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"https://www.kb.cert.org/vuls/id/355151"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"ACTi D, B, I, and E series cameras","vendor":"ACTi Corporation","versions":[{"status":"affected","version":"A1D-500-V6.11.31-AC"}]}],"datePublic":"2017-03-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-598","description":"CWE-598: Information Exposure Through Query Strings in GET Request","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-12-15T13:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"tags":["x_refsource_MISC"],"url":"https://twitter.com/hack3rsca/status/839599437907386368"},{"name":"96720","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/96720/info"},{"tags":["x_refsource_MISC"],"url":"https://twitter.com/Hfuhs/status/839252357221330944"},{"name":"VU#355151","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"https://www.kb.cert.org/vuls/id/355151"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2017-3185","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"ACTi D, B, I, and E series cameras","version":{"version_data":[{"version_value":"A1D-500-V6.11.31-AC"}]}}]},"vendor_name":"ACTi Corporation"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-598: Information Exposure Through Query Strings in GET Request"}]}]},"references":{"reference_data":[{"name":"https://twitter.com/hack3rsca/status/839599437907386368","refsource":"MISC","url":"https://twitter.com/hack3rsca/status/839599437907386368"},{"name":"96720","refsource":"BID","url":"http://www.securityfocus.com/bid/96720/info"},{"name":"https://twitter.com/Hfuhs/status/839252357221330944","refsource":"MISC","url":"https://twitter.com/Hfuhs/status/839252357221330944"},{"name":"VU#355151","refsource":"CERT-VN","url":"https://www.kb.cert.org/vuls/id/355151"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2017-3185","datePublished":"2017-12-15T14:00:00.000Z","dateReserved":"2016-12-05T00:00:00.000Z","dateUpdated":"2024-08-05T14:16:28.235Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-12-16 02:29:10","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-598","CWE-200","CWE-598 CWE-598: Information Exposure Through Query Strings in GET Request"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:acti:camera_firmware:a1d-500-v6.11.31-ac:*:*:*:*:*:*:*","matchCriteriaId":"C7A530FE-C83D-4CAA-9C23-8C9A8F96B34A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"3185","Ordinal":"1","Title":"CVE-2017-3185","CVE":"CVE-2017-3185","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"3185","Ordinal":"1","NoteData":"ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.","Type":"Description","Title":"CVE-2017-3185"},{"CveYear":"2017","CveId":"3185","Ordinal":"2","NoteData":"2017-12-15","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"3185","Ordinal":"3","NoteData":"2017-12-15","Type":"Other","Title":"Modified"}]}}}