Vulnerability Description
Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Faleemi | Fsc-880 Firmware | 00.01.01.0048p2 |
| Faleemi | Fsc-880 | - |
Related Weaknesses (CWE)
References
- https://medium.com/iotsploit/faleemi-fsc-880-multiple-security-vulnerabilities-eExploitThird Party Advisory
- https://medium.com/iotsploit/faleemi-fsc-880-multiple-security-vulnerabilities-eExploitThird Party Advisory
FAQ
What is CVE-2017-14743?
CVE-2017-14743 is a vulnerability with a CVSS score of 8.1 (HIGH). Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.
How severe is CVE-2017-14743?
CVE-2017-14743 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14743?
Check the references section above for vendor advisories and patch information. Affected products include: Faleemi Fsc-880 Firmware, Faleemi Fsc-880.