10
CVSSv2

CVE-2010-4232

Published: 17/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote malicious users to bypass authentication via a // (slash slash) at the beginning of a URI, as demonstrated by the //system.html URI.

Vulnerable Product Search on Vulmon Subscribe to Product

camtron cmnc-200_firmware 1.102a-008

camtron cmnc-200

tecvoz cmnc-200_firmware 1.102a-008

tecvoz cmnc-200

Exploits

Finding 3: Web Based Administration Interface Bypass CVE: CVE-2010-4232 The CMNC-200 IP Camera has an administrative web interface that does not handle authentication properly Using a properly formatted request, an attacker can bypass the authentication mechanism The first example requires authentication: wwwipcameracom/systemhtml Wh ...
The Camtron CMNC-200 IP Camera suffers from buffer overflow, administrative bypass, default account and directory traversal vulnerabilities ...