Description
Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware 4.30 and earlier, allow remote authenticated users to cause a denial of service (reboot) via a malformed (1) path parameter to en/store_main.asp, (2) item parameter to en/account/accedit.asp, or (3) emailid parameter to en/smtpclient.asp. NOTE: this issue can be exploited without authentication by leveraging CVE-2014-1900.
Published: 2015-05-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2014-1963 Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware 4.30 and earlier, allow remote authenticated users to cause a denial of service (reboot) via a malformed (1) path parameter to en/store_main.asp, (2) item parameter to en/account/accedit.asp, or (3) emailid parameter to en/smtpclient.asp. NOTE: this issue can be exploited without authentication by leveraging CVE-2014-1900.
History

No history.

Subscriptions

Y-cam Ycb001 Ycb001 Firmware Ycb002 Ycb002 Firmware Ycb003 Ycb003 Firmware Ycb004 Ycb004 Firmware Ycbl03 Ycbl03 Firmware Ycblb3 Ycblb3 Firmware Ycblhd5 Ycblhd5 Firmware Yceb03 Yceb03 Firmware Yck002 Yck002 Firmware Yck003 Yck003 Firmware Yck004 Yck004 Firmware Ycw001 Ycw001 Firmware Ycw002 Ycw002 Firmware Ycw003 Ycw003 Firmware Ycw004 Ycw004 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T09:58:15.491Z

Reserved: 2014-02-07T00:00:00.000Z

Link: CVE-2014-1901

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-05-14T00:59:01.303

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-1901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses