CVE-2021-30167 Information
Jun 07, 2022
cve
Description
The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.meritlilin.com/assets/uploads/support/file/M00166-TW.pdf https://www.twcert.org.tw/tw/cp-132-4676-391a5-1.html https://www.chtsecurity.com/news/0b733a38-e616-4ff3-86a6-13e710643388 https://gist.github.com/keniver/86ebef688fb274b534da51ef1a84dd3e
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: