Vulnerability Description
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and password within the cookies of a session. If an attacker gained access to these session cookies, it would be possible to gain access to the username and password of the logged-in account.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sv3C | H.264 Poe Ip Camera Firmware | v2.3.4.2103-s50-ntd-b20170508b |
| Sv3C | Sv-B01Poe-1080P-L | - |
| Sv3C | Sv-B11Vpoe-1080P-L | - |
| Sv3C | Sv-D02Poe-1080P-L | - |
Related Weaknesses (CWE)
References
- https://www.bishopfox.com/news/2018/10/sv3c-l-series-hd-camera-multiple-vulnerabExploitThird Party Advisory
- https://www.bishopfox.com/news/2018/10/sv3c-l-series-hd-camera-multiple-vulnerabExploitThird Party Advisory
FAQ
What is CVE-2018-12674?
CVE-2018-12674 is a vulnerability with a CVSS score of 5.7 (MEDIUM). The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and password within the cookies of a session. If an attacker gained access to these ...
How severe is CVE-2018-12674?
CVE-2018-12674 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12674?
Check the references section above for vendor advisories and patch information. Affected products include: Sv3C H.264 Poe Ip Camera Firmware, Sv3C Sv-B01Poe-1080P-L, Sv3C Sv-B11Vpoe-1080P-L, Sv3C Sv-D02Poe-1080P-L.