CVE-2017-11510

An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator username and password via an ONVIF GetSnapshotUri request.
References
Link Resource
https://www.tenable.com/security/research/tra-2017-33 Exploit Third Party Advisory
https://www.tenable.com/security/research/tra-2017-33 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:wanscam:hw0021_firmware:11.6.5.1.1-20161213:*:*:*:*:*:*:*
cpe:2.3:h:wanscam:hw0021:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:07

Type Values Removed Values Added
References () https://www.tenable.com/security/research/tra-2017-33 - Exploit, Third Party Advisory () https://www.tenable.com/security/research/tra-2017-33 - Exploit, Third Party Advisory

Information

Published : 2018-03-28 17:29

Updated : 2024-11-21 03:07


NVD link : CVE-2017-11510

Mitre link : CVE-2017-11510

CVE.ORG link : CVE-2017-11510


JSON object : View

Products Affected

wanscam

  • hw0021_firmware
  • hw0021
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-522

Insufficiently Protected Credentials