CVE-2018-18004: Medium severity vivotek network camera vulnerability
Incorrect Access Control in modinetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X09a allows remote attackers to enable arbitrary system services via a URL parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-18004?
CVE-2018-18004 is a vulnerability that affects VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X09a. It allows remote attackers to enable arbitrary system services via a URL parameter.
How does CVE-2018-18004 impact VIVOTEK Network Camera Series products?
CVE-2018-18004 allows remote attackers to enable arbitrary system services by exploiting an Incorrect Access Control vulnerability in mod_inetd.cgi.
What is the severity of CVE-2018-18004?
CVE-2018-18004 has a medium severity rating with a CVSS score of 5.3.
Where can I find more information about CVE-2018-18004?
You can find more information about CVE-2018-18004 in the VIVOTEK Security Advisory VVTK-SA-2018-006-v1 and the associated blog post.
How do I fix the CVE-2018-18004 vulnerability?
To fix the CVE-2018-18004 vulnerability, update the firmware of the VIVOTEK Network Camera Series products to version XXXXXX-VVTK-0X09a or later.