CVE-2017-15236

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
11/10/2017
Last modified:
20/04/2025

Description

Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via a crafted request to TCP port 3001, as demonstrated by config* files and extendword.txt.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tiandy:tiandy_ip_camera_firmware:5.56.17.120:*:*:*:*:*:*:*
cpe:2.3:h:tiandy:tiandy_ip_camera:-:*:*:*:*:*:*:*