Vulnerability Description
Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remote code execution on cameras running the firmware when a victim logs into a specially crafted mobile app.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mipcm | Mipc Camera Firmware | 5.3.1.2003161406 |
| Mipcm | Mipc Camera | - |
Related Weaknesses (CWE)
References
- https://hackmd.io/%40_zOX-PXQQFmCETA_RZIgow/BkOhIU1oc
- https://hackmd.io/%40_zOX-PXQQFmCETA_RZIgow/BkOhIU1oc
- https://hackmd.io/@_zOX-PXQQFmCETA_RZIgow/BkOhIU1oc
FAQ
What is CVE-2022-40785?
CVE-2022-40785 is a vulnerability with a CVSS score of 8.8 (HIGH). Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remote code execution on cameras running the firmware wh...
How severe is CVE-2022-40785?
CVE-2022-40785 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40785?
Check the references section above for vendor advisories and patch information. Affected products include: Mipcm Mipc Camera Firmware, Mipcm Mipc Camera.