Advisories

UCanCode E-XD++ Visualization Enterprise Suite Untrusted Pointer Dereference RCE

Go Back
severity
high
date
Affecting
  • E-XD++ Visualization Enterprise Suite

  • An affected version range remains undefined

CWE
  • CWE-823 Use of Out-of-range Pointer Offset
CVSS
8.6
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Yakir Wizman
Description
JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.