Remote Information Disclosure Vulnerability in Amcrest IP Cameras
CVE-2024-12984
Key Information:
- Vendor
- Amcrest
- Status
- Ip2m-841b
- Ip2m-841w
- Ipc-ip2m-841b
- Ipc-ip3m-943b
- Vendor
- CVE Published:
- 27 December 2024
Badges
Summary
A significant vulnerability has been identified in several Amcrest IP camera models that allows for remote information disclosure through the web interface. The flaw impacts the webCapsConfig file, enabling attackers to potentially access sensitive information without any necessary credentials. Despite the early notification to the vendor regarding this security issue, no response has been documented, suggesting a lack of urgency in addressing the threat. Users of the affected devices should be aware of the risk and consider implementing preventive measures.
Affected Version(s)
IP2M-841B 20241211
IP2M-841W 20241211
IPC-IP2M-841B 20241211
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved