描述
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.
AI分析AI驱动
受影响产品
cellinxcellinx_nvt_-_ip_ptz_camera_firmware
3.2.0
cellinxcellinx_nvt_-_ip_ptz_camera_firmware
3.2.1
cellinxcellinx_nvt_-_ip_ptz_camera
-
参考资料
- https://www.gov.il/en/departments/faq/cve_advisoriesThird Party Advisory
- https://www.gov.il/en/departments/faq/cve_advisoriesThird Party Advisory