First published: Thu Jul 21 2022(Updated: )
The server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Axis M1125) to see FTP credentials in a cleartext HTTP traffic. These can be used for FTP access to the server.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citilog Citilog | =8.0 | |
Axis M1125 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28861 is a vulnerability in Citilog 8.0 that allows an attacker to see FTP credentials in cleartext HTTP traffic.
An attacker can exploit CVE-2022-28861 by being in a man-in-the-middle position between the server and the Axis M1125 smart camera, allowing them to intercept and view the FTP credentials.
The severity of CVE-2022-28861 is medium, with a severity value of 5.9.
Citilog 8.0 is affected by CVE-2022-28861.
To fix CVE-2022-28861, it is recommended to update Citilog 8.0 to the latest version and ensure that HTTP traffic between the server and the Axis M1125 smart camera is encrypted.