HIGH · 9.4

CVE-2014-8384

The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configuration, reboot the d...

Vulnerability Description

The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configuration, reboot the device, change the device name, and have other unspecified impact via a crafted request.

CVSS Score

9.4

HIGH

AV:N/AC:L/Au:N/C:N/I:C/A:C
Confidentiality
NONE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
InfocusIn3128Hd Firmware0.26
InfocusIn3128Hd-

References

FAQ

What is CVE-2014-8384?

CVE-2014-8384 is a vulnerability with a CVSS score of 9.4 (HIGH). The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configuration, reboot the d...

How severe is CVE-2014-8384?

CVE-2014-8384 has been rated HIGH with a CVSS base score of 9.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-8384?

Check the references section above for vendor advisories and patch information. Affected products include: Infocus In3128Hd Firmware, Infocus In3128Hd.