MEDIUM · 4.8

CVE-2019-10957

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to event configuration to s...

Vulnerability Description

Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to event configuration to store malicious code on the server, which could later be triggered by a legitimate user resulting in code execution within the user’s browser.

CVSS Score

4.8

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
GeutebrueckG-Code Eec-2400 Firmware<= 1.12.0.25
GeutebrueckG-Code Eec-2400-
GeutebrueckG-Cam Ebc-2110 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ebc-2110-
GeutebrueckG-Cam Ebc-2111 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ebc-2111-
GeutebrueckG-Cam Efd-2240 Firmware<= 1.12.0.25
GeutebrueckG-Cam Efd-2240-
GeutebrueckG-Cam Efd-2241 Firmware<= 1.12.0.25
GeutebrueckG-Cam Efd-2241-
GeutebrueckG-Cam Efd-2250 Firmware<= 1.12.0.25
GeutebrueckG-Cam Efd-2250-
GeutebrueckG-Cam Ethc-2230 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ethc-2230-
GeutebrueckG-Cam Ethc-2240 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ethc-2240-
GeutebrueckG-Cam Ethc-2239 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ethc-2239-
GeutebrueckG-Cam Ethc-2249 Firmware<= 1.12.0.25
GeutebrueckG-Cam Ethc-2249-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-10957?

CVE-2019-10957 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to event configuration to s...

How severe is CVE-2019-10957?

CVE-2019-10957 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-10957?

Check the references section above for vendor advisories and patch information. Affected products include: Geutebrueck G-Code Eec-2400 Firmware, Geutebrueck G-Code Eec-2400, Geutebrueck G-Cam Ebc-2110 Firmware, Geutebrueck G-Cam Ebc-2110, Geutebrueck G-Cam Ebc-2111 Firmware.