vendor:
IP CAM
by:
Sunplace Solutions - Soluciones Informáticas - #RE Remoteexecution.net
8.8
CVSS
HIGH
Full Info Disclosure
287
CWE
Product Name: IP CAM
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2015
Apexis IP CAM – Full Info Disclosure
A vulnerability in Apexis IP CAM allows an attacker to gain full information disclosure of the device. This vulnerability is due to improper authentication and authorization checks in the web interface. By sending a specially crafted request to the web interface, an attacker can gain access to the device's username and password, as well as other sensitive information. The affected models are APM-H602-MPC, APM-H803-MPC, APM-H901-MPC, APM-H501-MPC, APM-H403-MPC, and APM-H804.
Mitigation:
Ensure that authentication and authorization checks are properly implemented in the web interface.