HIGH · 7.2

CVE-2019-10956

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to ...

Vulnerability Description

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to execute commands as root.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GeutebrueckG-Code Eec-2400 Firmware<= 1.12.0.25
GeutebrueckG-Code Eec-2400-
GeutebrueckG-Cam Ebc-2110 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ebc-2110-
GeutebrueckG-Cam Ebc-2111 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ebc-2111-
GeutebrueckG-Cam Efd-2240 Firmware<= 1.12.0.25
GeutebrueckG-Cam Efd-2240-
GeutebrueckG-Cam Efd-2241 Firmware<= 1.12.0.25
GeutebrueckG-Cam Efd-2241-
GeutebrueckG-Cam Efd-2250 Firmware<= 1.12.0.25
GeutebrueckG-Cam Efd-2250-
GeutebrueckG-Cam Ethc-2230 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ethc-2230-
GeutebrueckG-Cam Ethc-2240 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ethc-2240-
GeutebrueckG-Cam Ethc-2239 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ethc-2239-
GeutebrueckG-Cam Ethc-2249 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ethc-2249-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-10956?

CVE-2019-10956 is a vulnerability with a CVSS score of 7.2 (HIGH). Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to ...

How severe is CVE-2019-10956?

CVE-2019-10956 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-10956?

Check the references section above for vendor advisories and patch information. Affected products include: Geutebrueck G-Code Eec-2400 Firmware, Geutebrueck G-Code Eec-2400, Geutebrueck G-Cam Ebc-2110 Firmware, Geutebrueck G-Cam Ebc-2110, Geutebrueck G-Cam Ebc-2111 Firmware.