Vulnerability Description
A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10001 could allow an attacker to reset the user accounts to factory defaults, without authentication.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Foscam | C1 Firmware | 2.52.2.43 |
| Foscam | C1 | - |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0384ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0384ExploitThird Party Advisory
FAQ
What is CVE-2017-2877?
CVE-2017-2877 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10001 could allow an attac...
How severe is CVE-2017-2877?
CVE-2017-2877 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-2877?
Check the references section above for vendor advisories and patch information. Affected products include: Foscam C1 Firmware, Foscam C1.