CERT-In Vulnerability Note
CIVN-2024-0314
Multiple Vulnerabilities in D3D Security IP Camera
Original Issue Date:October 04, 2024
Severity Rating: HIGH
Systems Affected
- D3D Security IP Camera D8801 - all versions
Overview
Multiple vulnerabilities have been reported in D3D Security IP Camera, which could allow a remote attacker to gain unauthorized access to sensitive information and live feed of the targeted device.
Description
1. Credential Leakage Vulnerability
(
CVE-2024-47789
)
This vulnerability exists in D3D Security IP Camera due to usage of weak authentication scheme of the HTTP header protocol where authorization tag contain a Base-64 encoded username and password. A remote attacker could exploit this vulnerability by crafting a HTTP packet leading to exposure of user credentials of the targeted device.
2. Missing Authorization Vulnerability
(
CVE-2024-47790
)
This vulnerability exists in D3D Security IP Camera due to usage of insecure Real-Time Streaming Protocol (RTSP) version for live video streaming. A remote attacker could exploit this vulnerability by crafting a RTSP packet leading to unauthorized access to live feed of the targeted device.
Credit
These vulnerabilities are reported by Priyanka R. Chaudhary, BITS Pilani, Hyderabad
Solution
As per the information provided by the vendor, the product has reached its End of Life (EOL) in January 2024 and is no longer supported by them. It is recommended to discontinue use of the product or replace with a supported product appropriately.
Note
- These vulnerabilities note are published to inform users about the presence of unpatched vulnerabilities and that the product is no longer supported by the vendor. Users are advised to assess and address the risk accordingly.
Vendor Information
D3D security
https://d3dsecurity.com/
References
D3D security
https://d3dsecurity.com/
CVE Name
CVE-2024-47789
CVE-2024-47790
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|