CVE-2022-28860: Medium severity citilog vulnerability
An authentication downgrade in the server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Axis M1125) to achieve HTTP access to the camera.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28860?
CVE-2022-28860 is a vulnerability in Citilog 8.0 that allows an attacker in a man-in-the-middle position to achieve HTTP access to the camera.
How severe is CVE-2022-28860?
CVE-2022-28860 has a severity keyword of 'medium' and a severity value of 5.9.
What is the impact of CVE-2022-28860?
CVE-2022-28860 allows an attacker to achieve HTTP access to the camera in a man-in-the-middle position.
How can I fix CVE-2022-28860?
To fix CVE-2022-28860, it is recommended to apply the latest patches and updates provided by Citilog.
Where can I find more information about CVE-2022-28860?
You can find more information about CVE-2022-28860 in the reference links: [Github](https://github.com/ErwanBroquaire/citilog-8.0-vulnerability), [Citilog Website](https://www.citilog.com), [Information Note](https://www.citilog.com/wp-content/uploads/2023/07/CitilogSAS_information_note_2021-10-18-English.pdf).