10
CVSSv2

CVE-2017-16566

Published: 17/11/2017 Updated: 20/04/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote malicious users to read or replace core system files including those used for authentication (such as passwd and shadow). This can be abused to take full root level control of the device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qacctv jooan_a5_ip_camera_firmware 2.3.36