漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456
Vulnerability Description
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary control protocol header to access live video streams, control pan and tilt motors, activate audio functions, and remotely restart the device.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Puwell IP Camera 授权问题漏洞
Vulnerability Description
Puwell IP Camera是中国Puwell公司的一系列网络摄像机。 Puwell IP Camera 2.x版本至4.x版本存在授权问题漏洞,该漏洞源于身份验证绕过,未经身份验证的攻击者可通过TCP端口23456发送符合协议的数据包,利用专有控制协议标头中未经验证的Session字段访问实时视频流、控制云台电机、激活音频功能并远程重启设备。
CVSS Information
N/A
Vulnerability Type
N/A