First published: Mon Jul 18 2022(Updated: )
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.
Credit: cna@cyber.gov.il cna@cyber.gov.il
Affected Software | Affected Version | How to fix |
---|---|---|
Cellinx Cellinx Nvt - Ip Ptz Camera Firmware | =3.2.0 | |
Cellinx Cellinx Nvt - Ip Ptz Camera Firmware | =3.2.1 | |
Cellinx Cellinx Nvt - Ip Ptz Camera |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.