CVE-2023-0773
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
19/09/2023
Last modified:
21/09/2023
Description
The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.<br />
<br />
Successful exploitation of this vulnerability could allow the attacker to gain complete control of the targeted device.<br />
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* | cipc-b2303.2.8.230105 (including) | |
| cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* | dipc-b1213.6.5.230215 (including) | |
| cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* | dipc-b1216.5.7.230109 (including) | |
| cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* | dipc-b1221.3.5.221202 (including) | |
| cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* | dipc-b1222.3.8.230223 (including) | |
| cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* | dipc-b1225.3.3.221123 (including) | |
| cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* | dipc-b1226.3.6.230105 (including) | |
| cpe:2.3:h:uniview:ipc322lb-sf28-a:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:uniview:ipc322lb-sf28-a_firmware:*:*:*:*:*:*:*:* | dipc-b1219.2.67.221019 (including) |
To consult the complete list of CPE names with products and versions, see this page



