Subscriber Discussion
Vicon Authentication Bypass Vulnerability Published
IPVMU Certified | 07/31/16 08:37pm
From SecurityFocus:
Remote unauthenticated users can add an administrator, operator, or guest accounts to various Vicon network cameras by navigating directly to a specific URL. The URL is missing authentication and gives you direct access to the form that creates new accounts. URL: http://<IP>/system/user_pop.php?method=add&ptz_use=0 . With an account, a user can view the live video and alter camera settings.
AFFECTED PRODUCTS AND VERSIONS
Confirmed in products: V920D, V922D, and V-CELL-HD
Agree
Disagree
Informative: 1
Unhelpful
Funny
Newest Discussions
Discussion | Posts | Latest |
---|---|---|
Started by
John Honovich
|
7
|
less than a minute by Undisclosed #4 |
Started by
John Honovich
|
26
|
about 1 hour by Undisclosed Manufacturer #10 |
Started by
John Honovich
|
18
|
43 minutes by Jarad Regan |
Started by
Carl Stoffers
|
18
|
about 2 hours by John Honovich |
Started by
Undisclosed Distributor #1
|
2
|
less than a minute by John Honovich |