Vulnerability Description
Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Planex | Cs-Qr20 Firmware | All versions |
| Planex | Cs-Qr20 | - |
| Planex | Cs-Qr10 Firmware | All versions |
| Planex | Cs-Qr10 | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU90766406/index.htmlThird Party Advisory
- https://www.planex.co.jp/products/cs-qr10/index.shtmlProduct
- https://www.planex.co.jp/products/cs-qr20/index.shtmlProduct
- https://jvn.jp/en/vu/JVNVU90766406/index.htmlThird Party Advisory
- https://www.planex.co.jp/products/cs-qr10/index.shtmlProduct
- https://www.planex.co.jp/products/cs-qr20/index.shtmlProduct
FAQ
What is CVE-2022-38399?
CVE-2022-38399 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by havin...
How severe is CVE-2022-38399?
CVE-2022-38399 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-38399?
Check the references section above for vendor advisories and patch information. Affected products include: Planex Cs-Qr20 Firmware, Planex Cs-Qr20, Planex Cs-Qr10 Firmware, Planex Cs-Qr10.