global.uniview.comVendor advisory
https://global.uniview.com/About_Us/Security/Notice/202309/976482_140493_0.htm CVE-2023-0773
CRITICAL
Unauthorized Access Control Vulnerability in Uniview IP Camera
Record summary
CVE-2023-0773 has a selected CVSS score of 9.1 (critical).
Description
The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability could allow the attacker to gain complete control of the targeted device.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Uniview IP Camera IPC322LB-SF28-ABrowse Uniview / Uniview IP Camera IPC322LB-SF28-ADefault status: unaffected | CVE List | CIPC-B2303.X.X.XXXXXX to ≤ CIPC-B2303.2.8.230105 | affected |
| DIPC-B1213.X.X.XXXXXX to ≤ DIPC-B1213.6.5.230215 | affected | ||
| DIPC-B1216.X.X.XXXXXX to ≤ DIPC-B1216.5.7.230109 | affected | ||
| DIPC-B1221.X.X.XXXXXX to ≤ DIPC-B1221.3.5.221202 | affected | ||
| DIPC-B1222.X.X.XXXXXX to ≤ DIPC-B1222.3.8.230223 | affected | ||
| DIPC-B1225.X.X.XXXXXX to ≤ DIPC-B1225.3.3.221123 | affected | ||
| DIPC-B1226.X.X.XXXXXX to ≤ DIPC-B1226.3.6.230105 | affected | ||
| DIPC-B1219.X.X.XXXXXX to ≤ DIPC-B1219.2.67.221019 | affected | ||
| DIPC-B1223.X.X.XXXXXX to ≤ DIPC-B1223.3.3.221123 | affected | ||
| DIPC-B1228.X.X.XXXXXX to ≤ DIPC-B1228.2.65.230207 | affected | ||
| DIPC-B1229.X.X.XXXXXX to ≤ DIPC-B1229.1.67.230104 | affected | ||
ip_camera_ipc322lb-sf28-aBrowse uniview / ip_camera_ipc322lb-sf28-aDefault status: unknown | CVE List | CIPC-B2303.X.X.XXXXXX to ≤ CIPC-B2303.2.8.230105 | affected |
| DIPC-B1213.X.X.XXXXXX to ≤ DIPC-B1213.6.5.230215 | affected | ||
| DIPC-B1216.X.X.XXXXXX to ≤ DIPC-B1216.5.7.230109 | affected | ||
| DIPC-B1221.X.X.XXXXXX to ≤ DIPC-B1221.3.5.221202 | affected | ||
| DIPC-B1222.X.X.XXXXXX to ≤ DIPC-B1222.3.8.230223 | affected | ||
| DIPC-B1225.X.X.XXXXXX to ≤ DIPC-B1225.3.3.221123 | affected | ||
| DIPC-B1226.X.X.XXXXXX to ≤ DIPC-B1226.3.6.230105 | affected | ||
| DIPC-B1219.X.X.XXXXXX to ≤ DIPC-B1219.2.67.221019 affected | affected | ||
| DIPC-B1223.X.X.XXXXXX to ≤ DIPC-B1223.3.3.221123 | affected | ||
| DIPC-B1228.X.X.XXXXXX to ≤ DIPC-B1228.2.65.230207 | affected | ||
| DIPC-B1229.X.X.XXXXXX to ≤ DIPC-B1229.1.67.230104 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-0773 cert-in.org.in
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0270