Record summary

CVE-2019-7315 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x versions exist only for other Genie Access products).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHGenie Access WIP3BVAF IP Camera - Local File InclusionCVSS 7.5

Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.X are vulnerable to local file inclusion via the web interface, as demonstrated by reading /etc/shadow.

Impact

An attacker can exploit this vulnerability to read sensitive files on the system.

Remediation

Apply the latest firmware update provided by the vendor to fix the local file inclusion vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2019cameragenielfiiotgenieaccessvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:h:genieaccess:wip3bvaf:-:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2