Lucene search

K
cve[email protected]CVE-2016-7834
HistoryApr 13, 2017 - 5:59 p.m.

CVE-2016-7834

2017-04-1317:59:00
CWE-200
web.nvd.nist.gov
18
sony
network cameras
firmware
information disclosure
cve-2016-7834
security vulnerability

3.3 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:P/I:N/A:N

8.8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.2%

SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, SNC-EM520, SNC-EM521, SNC-ZB550, SNC-ZM550, SNC-ZM551, SNC-EP550, SNC-EP580, SNC-ER550, SNC-ER550C, SNC-ER580, SNC-ER585, SNC-ER585H, SNC-ZP550, SNC-ZR550, SNC-EP520, SNC-EP521, SNC-ER520, SNC-ER521, SNC-ER521C network cameras with firmware before Ver.1.86.00 and SONY SNC-CX600, SNC-CX600W, SNC-EB600, SNC-EB600B, SNC-EB602R, SNC-EB630, SNC-EB630B, SNC-EB632R, SNC-EM600, SNC-EM601, SNC-EM602R, SNC-EM602RC, SNC-EM630, SNC-EM631, SNC-EM632R, SNC-EM632RC, SNC-VB600, SNC-VB600B, SNC-VB600B5, SNC-VB630, SNC-VB6305, SNC-VB6307, SNC-VB632D, SNC-VB635, SNC-VM600, SNC-VM600B, SNC-VM600B5, SNC-VM601, SNC-VM601B, SNC-VM602R, SNC-VM630, SNC-VM6305, SNC-VM6307, SNC-VM631, SNC-VM632R, SNC-WR600, SNC-WR602, SNC-WR602C, SNC-WR630, SNC-WR632, SNC-WR632C, SNC-XM631, SNC-XM632, SNC-XM636, SNC-XM637, SNC-VB600L, SNC-VM600L, SNC-XM631L, SNC-WR602CL network cameras with firmware before Ver.2.7.2 are prone to sensitive information disclosure. This may allow an attacker on the same local network segment to login to the device with administrative privileges and perform operations on the device.

Affected configurations

NVD
Node
sonysnc_series_firmwareRange1.8.5.00
AND
sonysnc-cx600Match-
OR
sonysnc-cx600wMatch-
OR
sonysnc-eb600Match-
OR
sonysnc-eb600bMatch-
OR
sonysnc-eb602rMatch-
OR
sonysnc-eb630Match-
OR
sonysnc-eb630bMatch-
OR
sonysnc-eb632rMatch-
OR
sonysnc-em600Match-
OR
sonysnc-em601Match-
OR
sonysnc-em602rMatch-
OR
sonysnc-em602rcMatch-
OR
sonysnc-em630Match-
OR
sonysnc-em631Match-
OR
sonysnc-em632rMatch-
OR
sonysnc-em632rcMatch-
OR
sonysnc-vb600Match-
OR
sonysnc-vb600bMatch-
OR
sonysnc-vb600b5Match-
OR
sonysnc-vb600lMatch-
OR
sonysnc-vb630Match-
OR
sonysnc-vb6305Match-
OR
sonysnc-vb6307Match-
OR
sonysnc-vb632dMatch-
OR
sonysnc-vb635Match-
OR
sonysnc-vm600Match-
OR
sonysnc-vm600bMatch-
OR
sonysnc-vm600b5Match-
OR
sonysnc-vm600lMatch-
OR
sonysnc-vm601Match-
OR
sonysnc-vm601bMatch-
OR
sonysnc-vm602rMatch-
OR
sonysnc-vm630Match-
OR
sonysnc-vm6305Match-
OR
sonysnc-vm6307Match-
OR
sonysnc-vm631Match-
OR
sonysnc-vm632rMatch-
OR
sonysnc-wr600Match-
OR
sonysnc-wr602Match-
OR
sonysnc-wr602cMatch-
OR
sonysnc-wr602clMatch-
OR
sonysnc-wr630Match-
OR
sonysnc-wr632Match-
OR
sonysnc-wr632cMatch-
OR
sonysnc-xm631Match-
OR
sonysnc-xm631lMatch-
OR
sonysnc-xm632Match-
OR
sonysnc-xm636Match-
OR
sonysnc-xm637Match-
Node
sonysnc_series_firmwareRange2.7.0
AND
sonysnc-ch115Match-
OR
sonysnc-ch120Match-
OR
sonysnc-ch160Match-
OR
sonysnc-ch220Match-
OR
sonysnc-ch260Match-
OR
sonysnc-dh120Match-
OR
sonysnc-dh120tMatch-
OR
sonysnc-dh160Match-
OR
sonysnc-dh220Match-
OR
sonysnc-dh220tMatch-
OR
sonysnc-dh260Match-
OR
sonysnc-eb520Match-
OR
sonysnc-em520Match-
OR
sonysnc-em521Match-
OR
sonysnc-ep520Match-
OR
sonysnc-ep521Match-
OR
sonysnc-ep550Match-
OR
sonysnc-ep580Match-
OR
sonysnc-er520Match-
OR
sonysnc-er521Match-
OR
sonysnc-er521cMatch-
OR
sonysnc-er550Match-
OR
sonysnc-er550cMatch-
OR
sonysnc-er580Match-
OR
sonysnc-er585Match-
OR
sonysnc-er585hMatch-
OR
sonysnc-zb550Match-
OR
sonysnc-zm550Match-
OR
sonysnc-zm551Match-
OR
sonysnc-zp550Match-
OR
sonysnc-zr550Match-

3.3 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:P/I:N/A:N

8.8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.2%

Related for CVE-2016-7834