Record summary

CVE-2021-33544 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 20, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE ListEBC-21xx 1.12.13.2affected
EBC-21xx 1.12.14.5affected
EFD-22xx 1.12.13.2affected
EFD-22xx 1.12.14.5affected
ETHC-22xx 1.12.13.2affected
ETHC-22xx 1.12.14.5affected
EWPC-22xx 1.12.13.2affected
EWPC-22xx 1.12.14.5affected
EBC-21xx to ≤ 1.12.0.27affected
EFD-22xx to ≤ 1.12.0.27affected
ETHC-22xx to ≤ 1.12.0.27affected
EWPC-22xx to ≤ 1.12.0.27affected
CVE ListEEC-2xx 1.12.13.2affected
EEC-2xx 1.12.14.5affected
EEN-20xx 1.12.13.2affected
EEN-20xx 1.12.14.5affected
EEC-2xx to ≤ 1.12.0.27affected
EEN-20xx to ≤ 1.12.0.27affected
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

MetasploitGeutebruck Multiple Remote Command ExecutionMetasploit exploitby Ibrahim Ayadhi +2 moreNot analyzed1 file

Ruby · linked to 8 vulnerabilities

Metasploit

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHGeutebruck - Remote Command InjectionCVSS 7.2

Geutebruck is susceptible to multiple vulnerabilities its web-based management interface that could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.

Impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the affected device, leading to unauthorized access, data theft, or further compromise of the network.

Remediation

Apply the latest security patches or firmware updates provided by Geutebruck to mitigate the vulnerability.

WeaknessesCWE-78
Authorsgy741
Template tagscve2021cvegeutebruckrceoastgeutebrueckvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:h:geutebrueck:g-cam_ebc-2110:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3