CVE-2023-0773
Unauthorized Access Control Vulnerability in Uniview IP Camera
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.1EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
19 Sep 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.
Successful exploitation of this vulnerability could allow the attacker to gain complete control of the targeted device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected products
Uniview · Uniview IP Camera IPC322LB-SF28-AWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →