The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.
Successful exploitation of this vulnerability could allow the attacker to gain complete control of the targeted device.
References
Link | Resource |
---|---|
https://global.uniview.com/About_Us/Security/Notice/202309/976482_140493_0.htm | Vendor Advisory |
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0270 | Third Party Advisory |
https://global.uniview.com/About_Us/Security/Notice/202309/976482_140493_0.htm | Vendor Advisory |
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0270 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
History
21 Nov 2024, 07:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://global.uniview.com/About_Us/Security/Notice/202309/976482_140493_0.htm - Vendor Advisory | |
References | () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0270 - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
21 Sep 2023, 19:24
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:* cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
First Time |
Uniview ipc322lb-sf28-a
Uniview Uniview ipc322lb-sf28-a Firmware |
|
References | (MISC) https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0270 - Third Party Advisory | |
References | (MISC) https://global.uniview.com/About_Us/Security/Notice/202309/976482_140493_0.htm - Vendor Advisory | |
CWE | CWE-287 |
19 Sep 2023, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-19 10:15
Updated : 2024-11-21 07:37
NVD link : CVE-2023-0773
Mitre link : CVE-2023-0773
CVE.ORG link : CVE-2023-0773
JSON object : View
Products Affected
uniview
- ipc322lb-sf28-a_firmware
- ipc322lb-sf28-a
CWE
CWE-287
Improper Authentication