First published: Wed Nov 07 2018(Updated: )
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetHostname method allows unauthenticated persistent XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opticam I5 Application Firmware | =2.21.1.128 | |
Opticam I5 System Firmware | =1.5.2.11 | |
Opticam i5 | ||
Foscam C2 Application Firmware | =2.72.1.32 | |
Foscam C2 System Firmware | =1.11.1.8 | |
Foscam C2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-19080.
The severity of CVE-2018-19080 is medium with a CVSS score of 6.1.
Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128 are affected by CVE-2018-19080.
CVE-2018-19080 allows unauthenticated persistent XSS on Foscam Opticam i5 devices.
To fix CVE-2018-19080, it is recommended to update the system firmware and application firmware of Foscam Opticam i5 devices to the latest versions available.