Vulnerability Description
Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to event configuration to store malicious code on the server, which could later be triggered by a legitimate user resulting in code execution within the user’s browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Geutebrueck | G-Code Eec-2400 Firmware | <= 1.12.0.25 |
| Geutebrueck | G-Code Eec-2400 | - |
| Geutebrueck | G-Cam Ebc-2110 Firmware | <= 1.12.0.25 |
| Geutebrueck | G-Cam Ebc-2110 | - |
| Geutebrueck | G-Cam Ebc-2111 Firmware | <= 1.12.0.25 |
| Geutebrueck | G-Cam Ebc-2111 | - |
| Geutebrueck | G-Cam Efd-2240 Firmware | <= 1.12.0.25 |
| Geutebrueck | G-Cam Efd-2240 | - |
| Geutebrueck | G-Cam Efd-2241 Firmware | <= 1.12.0.25 |
| Geutebrueck | G-Cam Efd-2241 | - |
| Geutebrueck | G-Cam Efd-2250 Firmware | <= 1.12.0.25 |
| Geutebrueck | G-Cam Efd-2250 | - |
| Geutebrueck | G-Cam Ethc-2230 Firmware | <= 1.12.0.25 |
| Geutebrueck | G-Cam Ethc-2230 | - |
| Geutebrueck | G-Cam Ethc-2240 Firmware | <= 1.12.0.25 |
| Geutebrueck | G-Cam Ethc-2240 | - |
| Geutebrueck | G-Cam Ethc-2239 Firmware | <= 1.12.0.25 |
| Geutebrueck | G-Cam Ethc-2239 | - |
| Geutebrueck | G-Cam Ethc-2249 Firmware | <= 1.12.0.25 |
| Geutebrueck | G-Cam Ethc-2249 | - |
Related Weaknesses (CWE)
References
- https://www.us-cert.gov/ics/advisories/ICSA-19-155-03Third Party AdvisoryUS Government Resource
- https://www.us-cert.gov/ics/advisories/ICSA-19-155-03Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2019-10957?
CVE-2019-10957 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to event configuration to s...
How severe is CVE-2019-10957?
CVE-2019-10957 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10957?
Check the references section above for vendor advisories and patch information. Affected products include: Geutebrueck G-Code Eec-2400 Firmware, Geutebrueck G-Code Eec-2400, Geutebrueck G-Cam Ebc-2110 Firmware, Geutebrueck G-Cam Ebc-2110, Geutebrueck G-Cam Ebc-2111 Firmware.