CVE-2016-2360: Critical severity milesight ip security camera firmware vulnerability
Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2360?
CVE-2016-2360 is considered a critical vulnerability due to the use of a default root password across multiple installations.
How do I fix CVE-2016-2360?
To fix CVE-2016-2360, change the default root password on the affected Milesight IP security cameras immediately after installation.
Who is affected by CVE-2016-2360?
Users of Milesight IP security cameras with firmware versions up to and including 2016-11-14 are affected by CVE-2016-2360.
What are the risks associated with CVE-2016-2360?
The risks associated with CVE-2016-2360 include unauthorized access and potential control over the security cameras.
Is CVE-2016-2360 an exploit or a vulnerability?
CVE-2016-2360 is classified as a vulnerability that can be exploited if the default root password is not changed.