First published: Fri Jul 07 2017(Updated: )
Cross-site request forgery (CSRF) vulnerability in TS-WPTCAM, TS-PTCAM, TS-PTCAM/POE, TS-WLC2, TS-WLCE, TS-WRLC firmware version 1.19 and earlier and TS-WPTCAM2 firmware version 1.01 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Iodata Ts-wptcam Camera Firmware | <=1.19 | |
Iodata Ts-wptcam Camera Firmware | ||
Iodata Ts-ptcam/poe Firmware | <=1.19 | |
Iodata Ts-ptcam Camera Firmware | ||
Iodata Ts-ptcam/poe Camera Firmware | <=1.19 | |
Iodata Ts-ptcam/poe Camera | ||
Iodata Ts-wlc2 Camera | <=1.19 | |
Iodata Ts-wlc2 Camera Firmware | ||
Iodata Ts-wlce Camera | <=1.19 | |
Iodata Ts-wlce Camera Firmware | ||
Iodata Ts-wrlc | <=1.19 | |
Iodata Ts-wrlc Camera Firmware | ||
Iodata Ts-wptcam2 | <=1.01 | |
Iodata Ts-wptcam2 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2223 has a medium severity rating as it allows remote attackers to hijack the authentication of administrators.
To fix CVE-2017-2223, update the firmware for affected devices to version 1.20 or later.
Devices affected by CVE-2017-2223 include Iodata TS-WPTCAM, TS-PTCAM, TS-PTCAM/POE, TS-WLC2, TS-WLCE, and TS-WRLC with firmware versions 1.19 and earlier.
CVE-2017-2223 is a cross-site request forgery (CSRF) vulnerability.
Yes, CVE-2017-2223 can be exploited remotely, allowing attackers to hijack administrator sessions.