Unauthenticated Snapshot Access in Denver SHO-110 IP Cameras
CVE-2021-4469
Key Information:
Badges
What is CVE-2021-4469?
Denver SHO-110 IP cameras have a security flaw that exposes a secondary HTTP service on TCP port 8001, which allows unauthorized access to the '/snapshot' endpoint. While the primary web interface on port 80 requires authentication, the backdoor service opens a pathway for attackers to obtain image snapshots directly. This vulnerability enables a remote attacker to capture snapshots continuously, potentially enabling them to reconstruct the camera's video feed, thereby breaching the confidentiality of the monitored area.
Affected Version(s)
SHO-110 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
