CRITICAL · 9.8

CVE-2017-16566

On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core system files including those used for authentication...

Vulnerability Description

On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core system files including those used for authentication (such as passwd and shadow). This can be abused to take full root level control of the device.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QacctvJooan A5 Ip Camera Firmware2.3.36
QacctvJooan A5 Ip Camera-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-16566?

CVE-2017-16566 is a vulnerability with a CVSS score of 9.8 (CRITICAL). On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core system files including those used for authentication...

How severe is CVE-2017-16566?

CVE-2017-16566 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-16566?

Check the references section above for vendor advisories and patch information. Affected products include: Qacctv Jooan A5 Ip Camera Firmware, Qacctv Jooan A5 Ip Camera.