CVE-2019-7315
Genie Access WIP3BVAF IP Camera - Local File Inclusion
Record summary
CVE-2019-7315 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x versions exist only for other Genie Access products).
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHGenie Access WIP3BVAF IP Camera - Local File InclusionCVSS 7.5
Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.X are vulnerable to local file inclusion via the web interface, as demonstrated by reading /etc/shadow.
Impact
An attacker can exploit this vulnerability to read sensitive files on the system.
Remediation
Apply the latest firmware update provided by the vendor to fix the local file inclusion vulnerability.
Source: ProjectDiscovery