CVE-2019-7315

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
17/06/2019
Last modified:
20/06/2019

Description

Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x versions exist only for other Genie Access products).

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:genieaccess:wip3bvaf_firmware:*:*:*:*:*:*:*:* 3.0 (including)
cpe:2.3:h:genieaccess:wip3bvaf:-:*:*:*:*:*:*:*