CVE Feed

    Dashboard / CVE / CVE-2018-8072

    CVE-2018-8072

    An issue was discovered on EDIMAX IC-3140W through 3.06, IC-5150W through 3.09, and IC-6220DC through 3.06 devices. The ipcam_cgi binary contains a stack-based buffer overflow that is possible to trigger from a remote unauthenticated /camera-cgi/public/getsysyeminfo.cgi?action=VALUE_HERE HTTP request: if the VALUE_HERE length is more than 0x400 (1024), it is possible to overwrite other values located on the stack due to an incorrect use of the strcpy() function.

    Published:Apr 26, 2018
    Last Modified:Nov 21, 2024
    EPS:Apr 26, 2018
    EPSS Score:0.00345
    CVSS Score:8.8

    Affected Products

    Vendor
    Edimax
    Product
    Ic-3140w
    Vendor
    Edimax
    Product
    Ic-3140w Firmware
    Vendor
    Edimax
    Product
    Ic-5150w
    Vendor
    Edimax
    Product
    Ic-5150w Firmware
    Vendor
    Edimax
    Product
    Ic-6220dc
    Vendor
    Edimax
    Product
    Ic-6220dc Firmware

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High