CVE-2024-39091

An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request.
References
Link Resource
https://joerngermany.github.io/mipc_vulnerability/ Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:annke:crater_2_firmware:5.4.1.221222153318:*:*:*:*:*:*:*
cpe:2.3:h:annke:crater_2:-:*:*:*:*:*:*:*

History

13 Aug 2024, 17:12

Type Values Removed Values Added
CWE CWE-78
References () https://joerngermany.github.io/mipc_vulnerability/ - () https://joerngermany.github.io/mipc_vulnerability/ - Mitigation, Third Party Advisory
Summary
  • (es) Una vulnerabilidad de inyección de comandos del sistema operativo en el componente ccm_debug del firmware de MIPC Camera anterior a v5.4.1.240424171021 permite a atacantes dentro de la misma red ejecutar código arbitrario a través de una solicitud HTML manipulada.
First Time Annke
Annke crater 2 Firmware
Annke crater 2
CPE cpe:2.3:o:annke:crater_2_firmware:5.4.1.221222153318:*:*:*:*:*:*:*
cpe:2.3:h:annke:crater_2:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

12 Aug 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-12 16:15

Updated : 2024-08-13 21:35


NVD link : CVE-2024-39091

Mitre link : CVE-2024-39091

CVE.ORG link : CVE-2024-39091


JSON object : View

Products Affected

annke

  • crater_2_firmware
  • crater_2
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')