CVE-2021-43442 Information
Jun 07, 2022
cve
Description
A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46) V5.0.9 build 151106 (Ax68) and V5.0.9 build 150615 (Ax78) due to a failure to allow the creation of more than one administrator account; however this can be bypassed by parameter maniulation using PUT and DELETE and by calling the ‘UserPermission’ endpoint with the ID of created account and set it to ‘admin’ userType successfully adding a second administrative account.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5688.php
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Share on: