CVE-2014-3895

UnknownEPSS 2.20%

Last modified

CVE-2014-3895 is a vulnerability of currently unknown severity. The I-O DATA TS-WLCAM camera with firmware 1.06 and earlier, TS-WLCAM/V camera with firmware 1.06 and earlier, TS-WPTCAM camera with firmware 1.08 and earlier, TS-PTCAM camera with firmware 1.08 and earlier, TS-PTCAM/POE camera with firmware 1.08 and earlier, and TS-WLC2 camera with firmware 1.02 and earlier allow remote attackers to bypass authentication, and consequently obtain sensitive credential and configuration data, via unspecified vectors.. EPSS estimates a 2.20% chance of exploitation in the next 30 days.

Description

The I-O DATA TS-WLCAM camera with firmware 1.06 and earlier, TS-WLCAM/V camera with firmware 1.06 and earlier, TS-WPTCAM camera with firmware 1.08 and earlier, TS-PTCAM camera with firmware 1.08 and earlier, TS-PTCAM/POE camera with firmware 1.08 and earlier, and TS-WLC2 camera with firmware 1.02 and earlier allow remote attackers to bypass authentication, and consequently obtain sensitive credential and configuration data, via unspecified vectors.

Metrics

EPSS Probability
2.20%

80.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IodataTs-Wlcam\/V Camera Firmware<= 1.0.6
IodataTs-Wlcam\/V CameraAll versions
IodataTs-Wptcam Camera Firmware<= 1.0.8
IodataTs-Wptcam CameraAll versions
IodataTs-Wlcam Camera Firmware<= 1.06
IodataTs-Wlcam CameraAll versions
IodataTs-Ptcam\/Poe Camera Firmware<= 1.08
IodataTs-Ptcam\/Poe CameraAll versions
IodataTs-Wlc2 Camera Firmware<= 1.02
IodataTs-Wlc2 CameraAll versions
IodataTs-Ptcam Camera Firmware<= 1.08
IodataTs-Ptcam CameraAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-3895?
The I-O DATA TS-WLCAM camera with firmware 1.06 and earlier, TS-WLCAM/V camera with firmware 1.06 and earlier, TS-WPTCAM camera with firmware 1.08 and earlier, TS-PTCAM camera with firmware 1.08 and earlier, TS-PTCAM/POE camera with firmware 1.08 and earlier, and TS-WLC2 camera with firmware 1.02 and earlier allow remote attackers to bypass authentication, and consequently obtain sensitive credential and configuration data, via unspecified vectors.
How severe is CVE-2014-3895?
Severity scoring for CVE-2014-3895 is pending analysis. The EPSS model estimates a 2.20% probability of exploitation in the next 30 days.
How do I fix CVE-2014-3895?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-3895?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST