Vulnerability Description
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10176
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Assaabloy | Yale Wipc-303W Firmware | >= 2.21, <= 2.31 |
| Assaabloy | Yale Wipc-303W | - |
Related Weaknesses (CWE)
References
- https://firedome.io/blog/firedome-discloses-0-day-vulnerabilities-in-yale-ip-camThird Party Advisory
- https://lp.firedome.io/hubfs/Yale%20WIPC-301W%20RCE%20Vulnerability%20Report%205ExploitThird Party Advisory
- https://whiterosezex.blogspot.com/2021/01/cve-2020-23826-rce-vulnerability-in.htThird Party Advisory
- https://firedome.io/blog/firedome-discloses-0-day-vulnerabilities-in-yale-ip-camThird Party Advisory
- https://lp.firedome.io/hubfs/Yale%20WIPC-301W%20RCE%20Vulnerability%20Report%205ExploitThird Party Advisory
- https://whiterosezex.blogspot.com/2021/01/cve-2020-23826-rce-vulnerability-in.htThird Party Advisory
FAQ
What is CVE-2020-23826?
CVE-2020-23826 is a vulnerability with a CVSS score of 8.8 (HIGH). The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10176
How severe is CVE-2020-23826?
CVE-2020-23826 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-23826?
Check the references section above for vendor advisories and patch information. Affected products include: Assaabloy Yale Wipc-303W Firmware, Assaabloy Yale Wipc-303W.