CVE-2017-11510

An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator username and password via an ONVIF GetSnapshotUri request.
References
Link Resource
https://www.tenable.com/security/research/tra-2017-33 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:wanscam:hw0021_firmware:11.6.5.1.1-20161213:*:*:*:*:*:*:*
cpe:2.3:h:wanscam:hw0021:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-03-28 17:29

Updated : 2024-02-28 16:25


NVD link : CVE-2017-11510

Mitre link : CVE-2017-11510

CVE.ORG link : CVE-2017-11510


JSON object : View

Products Affected

wanscam

  • hw0021
  • hw0021_firmware
CWE
CWE-522

Insufficiently Protected Credentials

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor