CVE-2014-8384

The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configuration, reboot the device, change the device name, and have other unspecified impact via a crafted request.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:infocus:in3128hd_firmware:0.26:*:*:*:*:*:*:*
cpe:2.3:h:infocus:in3128hd:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:18

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/131661/InFocus-IN3128HD-Projector-Missing-Authentication.html - Exploit () http://packetstormsecurity.com/files/131661/InFocus-IN3128HD-Projector-Missing-Authentication.html - Exploit
References () http://seclists.org/fulldisclosure/2015/Apr/88 - Exploit () http://seclists.org/fulldisclosure/2015/Apr/88 - Exploit
References () http://www.coresecurity.com/advisories/infocus-in3128hd-projector-multiple-vulnerabilities - Exploit, Vendor Advisory () http://www.coresecurity.com/advisories/infocus-in3128hd-projector-multiple-vulnerabilities - Exploit, Vendor Advisory

Information

Published : 2015-05-18 15:59

Updated : 2024-11-21 02:18


NVD link : CVE-2014-8384

Mitre link : CVE-2014-8384

CVE.ORG link : CVE-2014-8384


JSON object : View

Products Affected

infocus

  • in3128hd
  • in3128hd_firmware