SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, which allow remote attackers to bypass authentication and gain administrator access by setting the authLevel cookie to 255.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-10-19T22:00:00
Updated: 2024-08-05T08:38:06.337Z
Reserved: 2018-06-22T00:00:00
Link: CVE-2018-12666
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-10-19T22:29:00.257
Modified: 2024-11-21T03:45:38.117
Link: CVE-2018-12666
Redhat
No data.