vendor:
FI8620 PTZ Camera
by:
Core Security - Corelabs Advisory
7,5
CVSS
HIGH
Information Exposure [CWE-200]
200
CWE
Product Name: FI8620 PTZ Camera
Affected Version From: FOSCAM FI8620 PTZ Camera
Affected Version To: Other Foscam devices based on the same firmware
Patch Exists: No
Related CWE: CVE-2013-2574
CPE: h:foscam:fi8620_ptz_camera
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
FOSCAM IP-Cameras Improper Access Restrictions
Due to improper access restriction the FOSCAM FI8620 device [1] allows a remote attacker to browse and access arbitrary files from the following directories '/tmpfs/' and '/log/' without requiring authentication. This could allow a remote attacker to obtain valuable information such as access credentials, Wi-Fi configuration and other sensitive information in plain text.
Mitigation:
Do not expose the camera to internet unless absolutely necessary and have at least one proxy filtering HTTP requests to the following resources: '/tmpfs/config_backup.bin', '/tmpfs/config_restor.bin', '/tmpfs/ddns.conf', '/tmpfs/syslog.txt', '/log/syslog.txt'