Vulnerability Description
Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi passphrase hidden, but by editing/removing the style of the password field the password becomes visible which grants access to an internal network connected to the camera.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alecto | Dvc-215Ip Firmware | >= 63.1.1.137, < 63.1.1.173 |
| Alecto | Dvc-215Ip | - |
Related Weaknesses (CWE)
References
- https://support.alecto.nl/nl/support/solutions/articles/48001210271-kwetsbaarheiVendor Advisory
- https://support.alecto.nl/nl/support/solutions/articles/48001210271-kwetsbaarheiVendor Advisory
FAQ
What is CVE-2022-24610?
CVE-2022-24610 is a vulnerability with a CVSS score of 8.6 (HIGH). Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi passphrase hidden, but by editing/removing the style of the password field the p...
How severe is CVE-2022-24610?
CVE-2022-24610 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24610?
Check the references section above for vendor advisories and patch information. Affected products include: Alecto Dvc-215Ip Firmware, Alecto Dvc-215Ip.