An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can trigger read operations on an arbitrary file via Path Traversal in the TZ parameter, but cannot retrieve the data that is read. This causes a denial of service if the filename is, for example, /dev/random.
References
Link | Resource |
---|---|
http://www.microdigital.co.kr/ | Vendor Advisory |
https://pastebin.com/PSyqqs1g | Third Party Advisory |
https://www.microdigital.ru/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-08-06T22:26:19
Updated: 2019-08-06T22:26:19
Reserved: 2019-08-06T00:00:00
Link: CVE-2019-14701
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-08-06T23:15:12.367
Modified: 2019-08-13T18:46:04.673
Link: CVE-2019-14701
JSON object: View
Redhat Information
No data.
CWE