Vulnerability Description
Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Foscam | C1 | All versions |
| Foscam | C1 Lite | All versions |
| Foscam | C2 | All versions |
| Foscam | Fi9800Xe | All versions |
| Foscam | Fi9826P | All versions |
| Foscam | Fi9828P | All versions |
| Foscam | Fi9851P | All versions |
| Foscam | Fi9853Ep | All versions |
| Foscam | Fi9901Ep | All versions |
| Foscam | Fi9903P | All versions |
| Foscam | Fi9928P | All versions |
| Foscam | R2 | All versions |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/540388/30/0/threadedThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/540388/30/0/threadedThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-7648?
CVE-2017-7648 is a vulnerability with a CVSS score of 8.1 (HIGH). Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging kno...
How severe is CVE-2017-7648?
CVE-2017-7648 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7648?
Check the references section above for vendor advisories and patch information. Affected products include: Foscam C1, Foscam C1 Lite, Foscam C2, Foscam Fi9800Xe, Foscam Fi9826P.