Lucene search

K
cve[email protected]CVE-2018-6831
HistoryJul 09, 2018 - 5:29 p.m.

CVE-2018-6831

2018-07-0917:29:00
CWE-78
web.nvd.nist.gov
77
foscam
camera
vulnerability
command execution
cve-2018-6831
ntp server
security issue

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.7%

The setSystemTime function in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1 Lite V2 2.52.2.47 and earlier, FI9800P, FI9800P V2, FI9803P V2, FI9803P V3, and FI9851P V2 2.54.2.47 and earlier, FI9815P, FI9815P V2, FI9816P, and FI9816P V2, 2.51.2.47 and earlier, R2 and R4 2.71.1.59 and earlier, C2 and FI9961EP 2.72.1.59 and earlier, FI9900EP, FI9900P, and FI9901EP 2.74.1.59 and earlier, FI9928P 2.74.1.58 and earlier, FI9803EP and FI9853EP 2.22.2.31 and earlier, FI9803P and FI9851P 2.24.2.31 and earlier, FI9821P V2, FI9826P V2, FI9831P V2, and FI9821EP 2.21.2.31 and earlier, FI9821W V2, FI9831W, FI9826W, FI9821P, FI9831P, and FI9826P 2.11.1.120 and earlier, FI9818W V2 2.13.2.120 and earlier, FI9805W, FI9804W, FI9804P, FI9805E, and FI9805P 2.14.1.120 and earlier, FI9828P, and FI9828W 2.13.1.120 and earlier, and FI9828P V2 2.11.1.133 and earlier allows remote authenticated users to execute arbitrary commands via a ‘;’ in the ntpServer argument. NOTE: this issue exists because of an incomplete fix for CVE-2017-2849.

Affected configurations

NVD
Node
foscamc1_lite_firmwareRange2.82.2.33
AND
foscamc1_liteMatch3
Node
foscamc1_firmwareRange2.82.2.33
AND
foscamc1Match3
Node
foscamfi9800p_firmwareRange2.81.2.33
AND
foscamfi9800pMatch3
Node
foscamfi9821ep_firmwareRange2.81.2.33
AND
foscamfi9821epMatch2
Node
foscamfi9821p_firmwareRange2.81.2.33
AND
foscamfi9821pMatch3
Node
foscamfi9826p_firmwareRange2.81.2.33
AND
foscamfi9826pMatch3
Node
foscamfi9831p_firmwareRange2.81.2.33
AND
foscamfi9831pMatch3
Node
foscamc1_firmwareRange2.52.2.47
AND
foscamc1Match-
Node
foscamc1_firmwareRange2.52.2.47
AND
foscamc1Match2
Node
foscamc1_lite_firmwareRange2.52.2.47
AND
foscamc1_liteMatch-
Node
foscamc1_lite_firmwareRange2.52.2.47
AND
foscamc1_liteMatch2
Node
foscamfi9800p_firmwareRange2.54.2.47
AND
foscamfi9800pMatch-
Node
foscamfi9800p_firmwareRange2.54.2.47
AND
foscamfi9800pMatch2
Node
foscamfi9803p_firmwareRange2.54.2.47
AND
foscamfi9803pMatch2
Node
foscamfi9803p_firmwareRange2.54.2.47
AND
foscamfi9803pMatch3
Node
foscamfi9851p_firmwareRange2.54.2.47
AND
foscamfi9851pMatch2
Node
foscamfi9815p_firmwareRange2.51.2.47
AND
foscamfi9815pMatch-
Node
foscamfi9815p_firmwareRange2.51.2.47
AND
foscamfi9815pMatch2
Node
foscamfi9816p_firmwareRange2.51.2.47
AND
foscamfi9816pMatch-
Node
foscamfi9816p_firmwareRange2.51.2.47
AND
foscamfi9816pMatch2
Node
foscamr2_firmwareRange2.71.1.59
AND
foscamr2Match-
Node
foscamr4_firmwareRange2.71.1.59
AND
foscamr4Match-
Node
foscamc2_firmwareRange2.72.1.59
AND
foscamc2Match-
Node
foscamfi9961ep_firmwareRange2.72.1.59
AND
foscamfi9961epMatch-
Node
foscamfi9900ep_firmwareRange2.74.1.59
AND
foscamfi9900epMatch-
Node
foscamfi9900p_firmwareRange2.74.1.59
AND
foscamfi9900pMatch-
Node
foscamfi9901ep_firmwareRange2.74.1.59
AND
foscamfi9901epMatch-
Node
foscamfi9928p_firmwareRange2.74.1.58
AND
foscamfi9928pMatch-
Node
foscamfi9803ep_firmwareRange2.22.2.31
AND
foscamfi9803epMatch-
Node
foscamfi9853ep_firmwareRange2.22.2.31
AND
foscamfi9853epMatch-
Node
foscamfi9803p_firmwareRange2.24.2.31
AND
foscamfi9803pMatch-
Node
foscamfi9851p_firmwareRange2.24.2.31
AND
foscamfi9851pMatch-
Node
foscamfi9821p_firmwareRange2.21.2.31
AND
foscamfi9821pMatch2
Node
foscamfi9826p_firmwareRange2.21.2.31
AND
foscamfi9826pMatch2
Node
foscamfi9831p_firmwareRange2.21.2.31
AND
foscamfi9831pMatch2
Node
foscamfi9821ep_firmwareRange2.21.2.31
AND
foscamfi9821epMatch-
Node
foscamfi9821w_firmwareRange2.11.1.120
AND
foscamfi9821wMatch2
Node
foscamfi9831w_firmwareRange2.11.1.120
AND
foscamfi9831wMatch-
Node
foscamfi9826w_firmwareRange2.11.1.120
AND
foscamfi9826wMatch-
Node
foscamfi9821p_firmwareRange2.11.1.120
AND
foscamfi9821pMatch-
Node
foscamfi9831p_firmwareRange2.11.1.120
AND
foscamfi9831pMatch-
Node
foscamfi9826p_firmwareRange2.11.1.120
AND
foscamfi9826pMatch-
Node
foscamfi9818w_firmwareRange2.13.2.120
AND
foscamfi9818wMatch2
Node
foscamfi9805w_firmwareRange2.14.1.120
AND
foscamfi9805wMatch-
Node
foscamfi9804w_firmwareRange2.14.1.120
AND
foscamfi9804wMatch-
Node
foscamfi9804p_firmwareRange2.14.1.120
AND
foscamfi9804pMatch-
Node
foscamfi9805e_firmwareRange2.14.1.120
AND
foscamfi9805eMatch-
Node
foscamfi9805p_firmwareRange2.14.1.120
AND
foscamfi9805pMatch-
Node
foscamfi9828p_firmwareRange2.13.1.120
AND
foscamfi9828pMatch-
Node
foscamfi9828w_firmwareRange2.13.1.120
AND
foscamfi9828wMatch-
Node
foscamfi9828p_firmwareRange2.11.1.133
AND
foscamfi9828pMatch2

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.7%