CVE-2014-8384: Critical severity infocus in3128hd firmware vulnerability
The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to modify the DHCP server and device IP configuration, reboot the device, change the device name, and have other unspecified impact via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8384?
CVE-2014-8384 is considered to be of medium severity due to the potential for unauthorized remote access and configuration changes.
How do I fix CVE-2014-8384?
The recommended fix for CVE-2014-8384 is to update the firmware of the InFocus IN3128HD projector to a version that addresses this vulnerability.
Which devices are affected by CVE-2014-8384?
CVE-2014-8384 specifically affects the InFocus IN3128HD projector running firmware version 0.26.
What kind of access does CVE-2014-8384 allow to an attacker?
CVE-2014-8384 allows attackers to remotely modify DHCP settings, change IP configurations, reboot the device, and change its name.
Is CVE-2014-8384 a local or remote vulnerability?
CVE-2014-8384 is a remote vulnerability that can be exploited over a network without local access.