An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can trigger read operations on an arbitrary file via Path Traversal in the TZ parameter, but cannot retrieve the data that is read. This causes a denial of service if the filename is, for example, /dev/random.
References
Link Resource
http://www.microdigital.co.kr/ Vendor Advisory
https://pastebin.com/PSyqqs1g Third Party Advisory
https://www.microdigital.ru/ Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-08-06T22:26:19

Updated: 2019-08-06T22:26:19

Reserved: 2019-08-06T00:00:00


Link: CVE-2019-14701

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-08-06T23:15:12.367

Modified: 2019-08-13T18:46:04.673


Link: CVE-2019-14701

JSON object: View

cve-icon Redhat Information

No data.

CWE