Lucene search

K
cve[email protected]CVE-2022-28860
HistoryJul 21, 2022 - 4:15 p.m.

CVE-2022-28860

2022-07-2116:15:08
web.nvd.nist.gov
41
4
cve-2022-28860
authentication downgrade
citilog 8.0
man-in-the-middle attack
http access
axis m1125
smart camera
security vulnerability

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.3%

An authentication downgrade in the server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Axis M1125) to achieve HTTP access to the camera.

Affected configurations

NVD
Node
axism1125Match-
AND
citilogcitilogMatch8.0
CPENameOperatorVersion
citilog:citilogcitilogeq8.0

Social References

More

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

5.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.3%

Related for CVE-2022-28860