Lucene search

K
cvelistINCDCVELIST:CVE-2022-30620
HistoryJul 18, 2022 - 12:54 p.m.

CVE-2022-30620 Cellinx NVT – IP PTZ Camera Privilege Escalation

2022-07-1812:54:33
INCD
www.cve.org
4
cve-2022-30620
cellinx camera
privilege escalation
administrative privileges
configuration
cookie values

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

42.8%

On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: “1” to “0” privileges by changing the following cookie values from “is_admin”, “showConfig”. Administrative Privileges which allows changing various configuration in the camera.

CNA Affected

[
  {
    "product": "Cellinx NVT - IP PTZ Camera",
    "vendor": "Cellinx",
    "versions": [
      {
        "lessThan": "3.2.0*",
        "status": "affected",
        "version": "3.2.1",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

42.8%

Related for CVELIST:CVE-2022-30620