nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-33552 CVE-2021-33552
HIGH
UDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
Record summary
CVE-2021-33552 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit.
Description
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 9, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
E2 SeriesBrowse Geutebrück / E2 Series | CVE List | EBC-21xx 1.12.13.2 | affected |
| EBC-21xx 1.12.14.5 | affected | ||
| EFD-22xx 1.12.13.2 | affected | ||
| EFD-22xx 1.12.14.5 | affected | ||
| ETHC-22xx 1.12.13.2 | affected | ||
| ETHC-22xx 1.12.14.5 | affected | ||
| EWPC-22xx 1.12.13.2 | affected | ||
| EWPC-22xx 1.12.14.5 | affected | ||
| EBC-21xx to ≤ 1.12.0.27 | affected | ||
| EFD-22xx to ≤ 1.12.0.27 | affected | ||
| ETHC-22xx to ≤ 1.12.0.27 | affected | ||
| EWPC-22xx to ≤ 1.12.0.27 | affected | ||
Encoder G-CodeBrowse Geutebrück / Encoder G-Code | CVE List | EEC-2xx 1.12.13.2 | affected |
| EEC-2xx 1.12.14.5 | affected | ||
| EEN-20xx 1.12.13.2 | affected | ||
| EEN-20xx 1.12.14.5 | affected | ||
| EEC-2xx to ≤ 1.12.0.27 | affected | ||
| EEN-20xx to ≤ 1.12.0.27 | affected | ||
g-cam_ebc-2110Browse geutebruck / g-cam_ebc-2110 | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
MetasploitGeutebruck Multiple Remote Command ExecutionMetasploit exploitby Ibrahim Ayadhi +2 moreNot analyzed1 file
References
3us-cert.cisa.gov
https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03 randorisec.fr
https://www.randorisec.fr/fr/udp-technology-ip-camera-vulnerabilities