ID

VAR-201403-0386


CVE

CVE-2014-1911


TITLE

Foscam IP camera authentication bypass vulnerability

Trust: 0.8

sources: CERT/CC: VU#525132

DESCRIPTION

The Foscam FI8910W camera with firmware before 11.37.2.55 allows remote attackers to obtain sensitive video and image data via a blank username and password. The FI8910W Foscam IP camera running firmware version 11.37.2.54 fails to properly authenticate users. Foscam Provided by FI8910W There is an authentication bypass vulnerability (CWE-592) Exists. CWE-592: Authentication Bypass Issues http://cwe.mitre.org/data/definitions/592.htmlA remote attacker may be able to access video streaming or image files. FOSCAM IP-Cameras is a webcam device. FOSCAM FI8910W IP camera is prone to an authentication-bypass vulnerability. Attackers may exploit this issue to execute arbitrary commands, gain unauthorized access, or bypass intended security restrictions. Other attacks may also be possible. http://drupal.org/node/207891

Trust: 3.24

sources: NVD: CVE-2014-1911 // CERT/CC: VU#525132 // JVNDB: JVNDB-2014-001563 // CNVD: CNVD-2014-01501 // BID: 65931 // VULHUB: VHN-69850

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

category:['camera device']sub_category:camera

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2014-01501

AFFECTED PRODUCTS

vendor:foscammodel:fi8919wscope:lteversion:11.37.2.54

Trust: 1.0

vendor:foscammodel:fi8919wscope:eqversion: -

Trust: 1.0

vendor:foscam intelligentmodel: - scope: - version: -

Trust: 0.8

vendor:foscam intelligentmodel:fi8910wscope: - version: -

Trust: 0.8

vendor:foscam intelligentmodel:fi8910wscope:lteversion:version 11.37.2.54

Trust: 0.8

vendor: - model:foscam intelligent technology limited copyright. fi8910w foscam ip camerascope:eqversion:11.37.2.54

Trust: 0.6

vendor:foscammodel:fi8919wscope:eqversion:11.37.2.54

Trust: 0.6

vendor:foscam digitalmodel:fi8910wscope:eqversion:0

Trust: 0.3

sources: CERT/CC: VU#525132 // CNVD: CNVD-2014-01501 // BID: 65931 // JVNDB: JVNDB-2014-001563 // CNNVD: CNNVD-201403-140 // NVD: CVE-2014-1911

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2014-1911
value: HIGH

Trust: 1.6

nvd@nist.gov: CVE-2014-1911
value: HIGH

Trust: 1.0

CNVD: CNVD-2014-01501
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201403-140
value: HIGH

Trust: 0.6

VULHUB: VHN-69850
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-1911
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

NVD: CVE-2014-1911
severity: HIGH
baseScore: 7.8
vectorString: NONE
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2014-01501
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-69850
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#525132 // CNVD: CNVD-2014-01501 // VULHUB: VHN-69850 // JVNDB: JVNDB-2014-001563 // CNNVD: CNNVD-201403-140 // NVD: CVE-2014-1911

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

problemtype:CWE-255

Trust: 0.8

sources: VULHUB: VHN-69850 // JVNDB: JVNDB-2014-001563 // NVD: CVE-2014-1911

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201403-140

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201403-140

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001563

EXPLOIT AVAILABILITY

sources: CERT/CC: VU#525132

PATCH

title:Technical Support - Re: MJPEG .54 Firmware Bug - User Logon Bypassurl:http://foscam.us/forum/mjpeg-54-firmware-bug-user-logon-bypass-t8442-10.html#p40810

Trust: 0.8

title:Foscam Firmware Downloadsurl:http://foscam.us/firmware

Trust: 0.8

title:FOSCAM FI8910W IP Camera verifies the patch that bypasses the vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/44081

Trust: 0.6

sources: CNVD: CNVD-2014-01501 // JVNDB: JVNDB-2014-001563

EXTERNAL IDS

db:CERT/CCid:VU#525132

Trust: 4.2

db:NVDid:CVE-2014-1911

Trust: 3.5

db:BIDid:65931

Trust: 1.0

db:JVNid:JVNVU93348073

Trust: 0.8

db:JVNDBid:JVNDB-2014-001563

Trust: 0.8

db:CNNVDid:CNNVD-201403-140

Trust: 0.7

db:CNVDid:CNVD-2014-01501

Trust: 0.6

db:SECUNIAid:57056

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:SEEBUGid:SSVID-61680

Trust: 0.1

db:VULHUBid:VHN-69850

Trust: 0.1

sources: OTHER: None // CERT/CC: VU#525132 // CNVD: CNVD-2014-01501 // VULHUB: VHN-69850 // BID: 65931 // JVNDB: JVNDB-2014-001563 // CNNVD: CNNVD-201403-140 // NVD: CVE-2014-1911

REFERENCES

url:http://www.kb.cert.org/vuls/id/525132

Trust: 3.4

url:http://foscam.us/forum/mjpeg-54-firmware-bug-user-logon-bypass-t8442.html

Trust: 2.5

url:http://foscam.us/

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-1911

Trust: 0.8

url:http://jvn.jp/vu/jvnvu93348073/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-1911

Trust: 0.8

url:http://secunia.com/advisories/57056

Trust: 0.6

url:http://www.foscam.com/down3.aspx

Trust: 0.3

url:http://www.foscam.com/

Trust: 0.3

url:http://foscam.us/forum/mjpeg-54-firmware-bug-user-logon-bypass-t8442-10.html#p40810

Trust: 0.3

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // CERT/CC: VU#525132 // CNVD: CNVD-2014-01501 // VULHUB: VHN-69850 // BID: 65931 // JVNDB: JVNDB-2014-001563 // CNNVD: CNNVD-201403-140 // NVD: CVE-2014-1911

CREDITS

stiegl

Trust: 0.3

sources: BID: 65931

SOURCES

db:OTHERid: -
db:CERT/CCid:VU#525132
db:CNVDid:CNVD-2014-01501
db:VULHUBid:VHN-69850
db:BIDid:65931
db:JVNDBid:JVNDB-2014-001563
db:CNNVDid:CNNVD-201403-140
db:NVDid:CVE-2014-1911

LAST UPDATE DATE

2025-01-30T22:07:28.685000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#525132date:2014-03-03T00:00:00
db:CNVDid:CNVD-2014-01501date:2014-03-06T00:00:00
db:VULHUBid:VHN-69850date:2014-03-07T00:00:00
db:BIDid:65931date:2014-03-03T00:00:00
db:JVNDBid:JVNDB-2014-001563date:2014-03-07T00:00:00
db:CNNVDid:CNNVD-201403-140date:2014-03-11T00:00:00
db:NVDid:CVE-2014-1911date:2024-11-21T02:05:15.923

SOURCES RELEASE DATE

db:CERT/CCid:VU#525132date:2014-03-03T00:00:00
db:CNVDid:CNVD-2014-01501date:2014-03-06T00:00:00
db:VULHUBid:VHN-69850date:2014-03-06T00:00:00
db:BIDid:65931date:2014-03-03T00:00:00
db:JVNDBid:JVNDB-2014-001563date:2014-03-05T00:00:00
db:CNNVDid:CNNVD-201403-140date:2014-03-11T00:00:00
db:NVDid:CVE-2014-1911date:2014-03-06T11:55:05.473