Lucene search

K
cveMitreCVE-2014-8389
HistoryDec 28, 2017 - 2:29 a.m.

CVE-2014-8389

2017-12-2802:29:03
CWE-78
mitre
web.nvd.nist.gov
32
cve-2014-8389
airlive
firmware
hard-coded credentials
boa web server
security vulnerability
nvd
http requests

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

52.4%

cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the embedded Boa web server, which allows remote attackers to obtain user credentials via crafted HTTP requests.

Affected configurations

Nvd
Node
airlivebu-3026Match-
AND
airlivebu-3026_firmwareMatch1.43_21.08.2014
Node
airlivemd-3025Match-
AND
airlivemd-3025_firmwareMatch1.81_21.08.2014
Node
airlivewl-2000camMatch-
AND
airlivewl-2000cam_firmwareMatchlm.1.6.18_14.10.2011
Node
airlivepoe-200cam_v2Match-
AND
airlivepoe-200cam_v2_firmwareMatchlm.1.6.17.01
Node
airlivebu-2015Match-
AND
airlivebu-2015_firmwareMatch1.03.18_16.06.2014
VendorProductVersionCPE
airlivebu-3026-cpe:2.3:h:airlive:bu-3026:-:*:*:*:*:*:*:*
airlivebu-3026_firmware1.43_21.08.2014cpe:2.3:o:airlive:bu-3026_firmware:1.43_21.08.2014:*:*:*:*:*:*:*
airlivemd-3025-cpe:2.3:h:airlive:md-3025:-:*:*:*:*:*:*:*
airlivemd-3025_firmware1.81_21.08.2014cpe:2.3:o:airlive:md-3025_firmware:1.81_21.08.2014:*:*:*:*:*:*:*
airlivewl-2000cam-cpe:2.3:h:airlive:wl-2000cam:-:*:*:*:*:*:*:*
airlivewl-2000cam_firmwarelm.1.6.18_14.10.2011cpe:2.3:o:airlive:wl-2000cam_firmware:lm.1.6.18_14.10.2011:*:*:*:*:*:*:*
airlivepoe-200cam_v2-cpe:2.3:h:airlive:poe-200cam_v2:-:*:*:*:*:*:*:*
airlivepoe-200cam_v2_firmwarelm.1.6.17.01cpe:2.3:o:airlive:poe-200cam_v2_firmware:lm.1.6.17.01:*:*:*:*:*:*:*
airlivebu-2015-cpe:2.3:h:airlive:bu-2015:-:*:*:*:*:*:*:*
airlivebu-2015_firmware1.03.18_16.06.2014cpe:2.3:o:airlive:bu-2015_firmware:1.03.18_16.06.2014:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

52.4%