nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-33543 CVE-2021-33543
CRITICAL
UDP Technology/Geutebrück camera devices: Authentication Bypass
Record summary
CVE-2021-33543 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user authentication settings. This can lead to manipulation of the device and denial of service.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
E2 SeriesBrowse Geutebrück / E2 Series | CVE List | EBC-21xx 1.12.13.2 | affected |
| EBC-21xx 1.12.14.5 | affected | ||
| EFD-22xx 1.12.13.2 | affected | ||
| EFD-22xx 1.12.14.5 | affected | ||
| ETHC-22xx 1.12.13.2 | affected | ||
| ETHC-22xx 1.12.14.5 | affected | ||
| EWPC-22xx 1.12.13.2 | affected | ||
| EWPC-22xx 1.12.14.5 | affected | ||
| EBC-21xx to ≤ 1.12.0.27 | affected | ||
| EFD-22xx to ≤ 1.12.0.27 | affected | ||
| ETHC-22xx to ≤ 1.12.0.27 | affected | ||
| EWPC-22xx to ≤ 1.12.0.27 | affected | ||
Encoder G-CodeBrowse Geutebrück / Encoder G-Code | CVE List | EEC-2xx 1.12.13.2 | affected |
| EEC-2xx 1.12.14.5 | affected | ||
| EEN-20xx 1.12.13.2 | affected | ||
| EEN-20xx 1.12.14.5 | affected | ||
| EEC-2xx to ≤ 1.12.0.27 | affected | ||
| EEN-20xx to ≤ 1.12.0.27 | affected |
Proofs of concept
1Catalogued exploits
MetasploitGeutebruck Multiple Remote Command ExecutionMetasploit exploitby Ibrahim Ayadhi +2 moreNot analyzed1 file
References
3us-cert.cisa.govConfirmation
https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03 randorisec.frConfirmation
https://www.randorisec.fr/fr/udp-technology-ip-camera-vulnerabilities