Cross-Site Scripting in VIVOTEK Network Cameras
CVE-2018-18244

6.1MEDIUM

Key Information:

Vendor

Vivotek

Status
Vendor
CVE Published:
3 January 2019

What is CVE-2018-18244?

This vulnerability affects VIVOTEK Network Camera Series products by allowing remote attackers to execute arbitrary JavaScript code through the manipulation of the HTTP Referer Header. This can be particularly dangerous as it enables unauthorized actions and data access, potentially compromising the security of affected camera systems. Keeping firmware updated is essential to mitigate such risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.