Brute Force Vulnerability in Amcrest IPM-721S Devices
CVE-2017-8227

9.8CRITICAL

Key Information:

Vendor

Amcrest

Vendor
CVE Published:
3 July 2019

What is CVE-2017-8227?

The Amcrest IPM-721S camera series exhibits a vulnerability that permits attackers to execute brute force attacks on user credentials without triggering account lockout mechanisms when utilizing the ONVIF specification. While the device incorporates a timeout policy after multiple incorrect password attempts via the web interface or HTTP API, this protection is absent for connections made through ONVIF. This disparity allows malicious actors to repeatedly attempt to access the device, potentially gaining unauthorized control over the camera system. Examination of the firmware reveals the vulnerable binary responsible for implementing credential checks, highlighting significant security risks associated with this flaw.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.