Microdigital
Microdigital Mdc-n4090 Firmware: vulnerabilidades y CVE
Microdigital Mdc-n4090 Firmware tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-14709 | Crítica (9.8) | 1.8% | — | 6 ago 2019 | A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain… |
| CVE-2019-14708 | Crítica (9.8) | 4.5% | — | 6 ago 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the action parameter leads to remote code execution in the context of the nobody account. |
| CVE-2019-14707 | Alta (7.2) | 3.0% | — | 6 ago 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The firmware update process is insecure, leading to remote code execution. The attacker can provide arbitrary firmware in a .dat… |
| CVE-2019-14706 | Alta (7.5) | 2.1% | — | 6 ago 2019 | A denial of service issue in HTTPD was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker without authorization can upload a file to upload.php with a filename longer than 256… |
| CVE-2019-14705 | Alta (7.2) | 1.6% | — | 6 ago 2019 | An Incorrect Access Control issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5 because any valid cookie can be used to make requests as an admin. |
| CVE-2019-14704 | Crítica (9.8) | 1.9% | — | 6 ago 2019 | An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field. |
| CVE-2019-14703 | Alta (8.8) | 0.72% | — | 6 ago 2019 | A CSRF issue was discovered in webparam?user&action=set¶m=add in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 to create an admin account. |
| CVE-2019-14702 | Crítica (9.8) | 1.7% | — | 6 ago 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. SQL injection vulnerabilities exist in 13 forms that are reachable through HTTPD. An attacker can, for example, create an admin… |
| CVE-2019-14701 | Alta (7.5) | 2.3% | — | 6 ago 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can trigger read operations on an arbitrary file via Path Traversal in the TZ parameter, but cannot retrieve the… |
| CVE-2019-14700 | Alta (7.5) | 2.1% | — | 6 ago 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. There is disclosure of the existence of arbitrary files via Path Traversal in HTTPD. This occurs because the filename specified… |
| CVE-2019-14699 | Crítica (9.8) | 6.0% | — | 6 ago 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filename parameter for remote code execution as root. This occurs in the… |
| CVE-2019-14698 | Crítica (9.8) | 4.5% | — | 6 ago 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. In a CGI program running under the HTTPD web server, a buffer overflow in the param parameter leads to remote code execution in… |