vendor:
Foscam Video Management System
by:
Alessandro Magnosi
7.5
CVSS
HIGH
Denial of Service (DoS) Local
119
CWE
Product Name: Foscam Video Management System
Affected Version From: 1.1.6.6
Affected Version To: 1.1.6.6
Patch Exists: YES
Related CWE: N/A
CPE: a:foscam:foscam_video_management_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 SP1 x86 en, Windows 10 Pro x64 it
2019
Foscam Video Management System 1.1.6.6 – ‘UID’ Denial of Service (PoC)
A buffer overflow vulnerability exists in Foscam Video Management System 1.1.6.6, which could allow an attacker to cause a denial of service condition. An attacker must first run a python code to create a file containing a large amount of data. The attacker must then copy the content of the file into the UID field of the Add Device page in the FoscamVMS application. This will cause the application to crash.
Mitigation:
Upgrade to the latest version of Foscam Video Management System.