vendor:
CMNC-200 IP Camera
by:
None
4,3
CVSS
MEDIUM
Denial of Service
400
CWE
Product Name: CMNC-200 IP Camera
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2010-4234
CPE: h:cmnc:cmnc-200_ip_camera
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2010
Camera Denial of Service
The CMNC-200 IP Camera has a built-in web server that is vulnerable to denial of service attacks. Sending multiple requests in parallel to the web server may cause the camera to reboot. Requests with long cookie header makes the IP camera reboot a few seconds faster, however the same can be accomplished with requests of any size. The example code below is able to reboot the IP cameras in less than a minute in a local network.
Mitigation:
Limit the number of requests to the web server, and ensure that the cookie header is not too long.