Telnet Credential Vulnerability in Smartwares Cameras
CVE-2024-13893
7.5HIGH
What is CVE-2024-13893?
Smartwares cameras, including models CIP-37210AT and C724IP, exhibit a vulnerability where shared telnet service credentials can be compromised. This occurs in firmware versions up to 3.3.0, with the password hashes retrievable via physical access to the SPI connected memory. The telnet service can be activated by creating a specially named folder on the inserted SD card. The absence of a response from the vendor regarding reports raises concerns about the patching status and the potential for other devices with similar firmware to harbor the same vulnerability. Users are advised to remain vigilant as newer firmware versions may also be at risk.
Affected Version(s)
C724IP 0 <= 3.3.0
CIP-37210AT 0 <= 3.3.0
References
CVSS V4
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michał Majchrowicz (Afine Team)
Marcin Wyczechowski (Afine Team)
