Vulnerability Description
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filename parameter for remote code execution as root. This occurs in the Mainproc executable file, which can be run from the HTTPD web server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microdigital | Mdc-N4090 Firmware | <= 6400.0.8.5 |
| Microdigital | Mdc-N4090 | - |
| Microdigital | Mdc-N4090W Firmware | <= 6400.0.8.5 |
| Microdigital | Mdc-N4090W | - |
| Microdigital | Mdc-N2190V Firmware | <= 6400.0.8.5 |
| Microdigital | Mdc-N2190V | - |
Related Weaknesses (CWE)
References
- http://www.microdigital.co.kr/Vendor Advisory
- https://pastebin.com/PSyqqs1gThird Party Advisory
- https://www.microdigital.ru/Vendor Advisory
- http://www.microdigital.co.kr/Vendor Advisory
- https://pastebin.com/PSyqqs1gThird Party Advisory
- https://www.microdigital.ru/Vendor Advisory
FAQ
What is CVE-2019-14699?
CVE-2019-14699 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filename parameter for remote code execution as root. Thi...
How severe is CVE-2019-14699?
CVE-2019-14699 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-14699?
Check the references section above for vendor advisories and patch information. Affected products include: Microdigital Mdc-N4090 Firmware, Microdigital Mdc-N4090, Microdigital Mdc-N4090W Firmware, Microdigital Mdc-N4090W, Microdigital Mdc-N2190V Firmware.