CVE-2017-3185 Information
Feb 14, 2021
cve
Description
ACTi cameras including the D B I and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password which can expose that information through the browser’s history referrers web logs and other sources.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/96720/info https://twitter.com/hack3rsca/status/839599437907386368 https://twitter.com/Hfuhs/status/839252357221330944 https://www.kb.cert.org/vuls/id/355151
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: