First published: Fri Oct 25 2019(Updated: )
Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Milesight IP security camera firmware | <=2016-11-14 | |
Milesight NCR Camera |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2360 is considered a critical vulnerability due to the use of a default root password across multiple installations.
To fix CVE-2016-2360, change the default root password on the affected Milesight IP security cameras immediately after installation.
Users of Milesight IP security cameras with firmware versions up to and including 2016-11-14 are affected by CVE-2016-2360.
The risks associated with CVE-2016-2360 include unauthorized access and potential control over the security cameras.
CVE-2016-2360 is classified as a vulnerability that can be exploited if the default root password is not changed.