The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.
Successful exploitation of this vulnerability could allow the attacker to gain complete control of the targeted device.
.This CVE has a CVSS3.1 score of 9.1 and a Base Severity of CRITICAL.
Info | Details |
---|---|
CVE ID | CVE-2023-0773 |
CVE State | PUBLISHED |
BaseScore | 9.1 |
BaseSeverity | CRITICAL |
VectorString | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Version | NA |
References for CVE-2023-0773 :
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0270
https://global.uniview.com/About_Us/Security/Notice/202309/976482_140493_0.htm
Metric Type | Metric Score |
---|---|
AttackVector(AV) | NETWORK |
AttackComplexity(AC) | LOW |
PrivilegesRequired(PR) | NONE |
UserInteraction(UI) | NONE |
Scope(S) | UNCHANGED |
Confidentiality(C) | HIGH |
Availability(A) | HIGH |
Integrity(I) | NONE |