← All CVEs

CVE-2017-17106

critical · 9.8

Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerability exists because of a lack of authentication checks in requests to CGI pages.

9.8
CVSS
15.3%
EPSS (exploit prob.)
97th
EPSS percentile
2017-12-19
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-522

Affected products

VendorProductAffected versions
zivifpr115-204-p-rs_firmware2.3.4.2103
zivifpr115-204-p-rsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-17106