CVE-2023-0773

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
19/09/2023
Last modified:
21/09/2023

Description

The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.<br /> <br /> Successful exploitation of this vulnerability could allow the attacker to gain complete control of the targeted device.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* cipc-b2303.2.8.230105 (including)
cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:*
cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* dipc-b1213.6.5.230215 (including)
cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:*
cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* dipc-b1216.5.7.230109 (including)
cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:*
cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* dipc-b1221.3.5.221202 (including)
cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:*
cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* dipc-b1222.3.8.230223 (including)
cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:*
cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* dipc-b1225.3.3.221123 (including)
cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:*
cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* dipc-b1226.3.6.230105 (including)
cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:*
cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* dipc-b1219.2.67.221019 (including)