|
223901
|
9.8 |
CRITICAL
Network
|
microdigital
|
mdc-n4090_firmware mdc-n4090w_firmware mdc-n2190v_firmware
|
A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, th…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-14709
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223902
|
9.8 |
CRITICAL
Network
|
microdigital
|
mdc-n4090_firmware mdc-n4090w_firmware mdc-n2190v_firmware
|
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the action parameter leads to remote code execution in the context of the nobody accoun…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-14708
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223903
|
7.2 |
HIGH
Network
|
microdigital
|
mdc-n4090_firmware mdc-n4090w_firmware mdc-n2190v_firmware
|
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The firmware update process is insecure, leading to remote code execution. The attacker can provide arbitrar…
|
NVD-CWE-noinfo
|
CVE-2019-14707
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223904
|
7.5 |
HIGH
Network
|
microdigital
|
mdc-n4090_firmware mdc-n4090w_firmware mdc-n2190v_firmware
|
A denial of service issue in HTTPD was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker without authorization can upload a file to upload.php with a filename …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-14706
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223905
|
7.2 |
HIGH
Network
|
microdigital
|
mdc-n4090_firmware mdc-n4090w_firmware mdc-n2190v_firmware
|
An Incorrect Access Control issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5 because any valid cookie can be used to make requests as an admin.
|
CWE-287
Improper Authentication
|
CVE-2019-14705
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223906
|
9.8 |
CRITICAL
Network
|
microdigital
|
mdc-n4090_firmware mdc-n4090w_firmware mdc-n2190v_firmware
|
An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-14704
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223907
|
8.8 |
HIGH
Network
|
microdigital
|
mdc-n4090_firmware mdc-n4090w_firmware mdc-n2190v_firmware
|
A CSRF issue was discovered in webparam?user&action=set¶m=add in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 to create an admin account.
|
CWE-352
Origin Validation Error
|
CVE-2019-14703
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223908
|
9.8 |
CRITICAL
Network
|
microdigital
|
mdc-n4090_firmware mdc-n4090w_firmware mdc-n2190v_firmware
|
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. SQL injection vulnerabilities exist in 13 forms that are reachable through HTTPD. An attacker can, for examp…
|
CWE-89
SQL Injection
|
CVE-2019-14702
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223909
|
7.5 |
HIGH
Network
|
microdigital
|
mdc-n4090_firmware mdc-n4090w_firmware mdc-n2190v_firmware
|
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can trigger read operations on an arbitrary file via Path Traversal in the TZ parameter, but can…
|
CWE-22
Path Traversal
|
CVE-2019-14701
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223910
|
7.5 |
HIGH
Network
|
microdigital
|
mdc-n4090_firmware mdc-n4090w_firmware mdc-n2190v_firmware
|
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. There is disclosure of the existence of arbitrary files via Path Traversal in HTTPD. This occurs because the…
|
CWE-22
Path Traversal
|
CVE-2019-14700
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|