SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system commands or disrupt service.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41854 | SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system commands or disrupt service. |
Fixes
Solution
Update firmware version to v2.2046 or later.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7334-351fb-1.html |
|
History
Mon, 14 Oct 2024 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system commands or disrupt service. | SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system commands or disrupt service. |
| Weaknesses | CWE-78 |
Wed, 02 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spotcam Co Ltd
Spotcam Co Ltd spotcam Sense |
|
| CPEs | cpe:2.3:a:spotcam_co_ltd:spotcam_sense:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Spotcam Co Ltd
Spotcam Co Ltd spotcam Sense |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-10-14T03:32:16.132Z
Reserved: 2023-07-12T00:37:03.717Z
Link: CVE-2023-38027
Updated: 2024-08-02T17:23:27.968Z
Status : Modified
Published: 2023-08-28T04:15:17.160
Modified: 2024-11-21T08:12:42.133
Link: CVE-2023-38027
No data.
OpenCVE Enrichment
No data.
EUVD