CVE-2018-12675
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpected endpoint.
Published:Oct 19, 2018
Last Modified:Nov 21, 2024
EPS:Oct 19, 2018
EPSS Score:0.09632
CVSS Score:6.1
Affected Products
Vendor
Product
Action
Vendor
Sv3c
Product
H.264 Poe Ip Camera Firmware
Sv3c
H.264 Poe Ip Camera Firmware
Vendor
Sv3c
Product
Sv-b01poe-1080p-l
Sv3c
Sv-b01poe-1080p-l
Vendor
Sv3c
Product
Sv-b11vpoe-1080p-l
Sv3c
Sv-b11vpoe-1080p-l
Vendor
Sv3c
Product
Sv-d02poe-1080p-l
Sv3c
Sv-d02poe-1080p-l
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
