CRITICAL · 9.8

CVE-2018-18602

The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.

Vulnerability Description

The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Guardzilla360 Outdoor Firmware-
Guardzilla360 Outdoor-
Guardzilla180 Outdoor Firmware-
Guardzilla180 Outdoor-
Guardzilla360 Indoor Firmware-
Guardzilla360 Indoor-
Guardzilla180 Indoor Firmware-
Guardzilla180 Indoor-
GuardzillaOutdoor Hd Camera Firmware-
GuardzillaOutdoor Hd Camera-
GuardzillaIndoor Hd Camera Firmware-
GuardzillaIndoor Hd Camera-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-18602?

CVE-2018-18602 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.

How severe is CVE-2018-18602?

CVE-2018-18602 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-18602?

Check the references section above for vendor advisories and patch information. Affected products include: Guardzilla 360 Outdoor Firmware, Guardzilla 360 Outdoor, Guardzilla 180 Outdoor Firmware, Guardzilla 180 Outdoor, Guardzilla 360 Indoor Firmware.