CVE-2017-10719
Last modified
CVE-2017-10719 is a vulnerability of currently unknown severity. Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has default Wi-Fi credentials that are exactly the same for every device. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car garages, and also in some cases in the medical clinics to get access to areas that are difficult for a human being to reach. EPSS estimates a 2.07% chance of exploitation in the next 30 days.
Description
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has default Wi-Fi credentials that are exactly the same for every device. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car garages, and also in some cases in the medical clinics to get access to areas that are difficult for a human being to reach. Any breach of this system can allow an attacker to get access to video feed and pictures viewed by that user and might allow them to get a foot hold in air gapped networks especially in case of nation critical infrastructure/industries.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ishekar | Endoscope Camera Firmware | All versions |
References
- http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.htmlThird Party Advisory, VDB Entry
- https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdfExploit, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jun/8Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/153241/Shekar-Endoscope-Weak-Default-Settings-Memory-Corruption.htmlThird Party Advisory, VDB Entry
- https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Shekar_boriscope_sec_issues.pdfExploit, Third Party Advisory
- https://seclists.org/bugtraq/2019/Jun/8Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-10719?
How severe is CVE-2017-10719?
How do I fix CVE-2017-10719?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-10706When Antiy Antivirus Engine before 5.0.0.05171547 scans a sp…
- CVE-2017-10708An issue was discovered in Apport through 2.20.x. In apport/…
- CVE-2017-10709The lockscreen on Elephone P9000 devices (running Android 6.…
- CVE-2017-1071Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2017-10711In SimpleRisk 20170614-001, a CSRF attack on reset.php (aka …
- CVE-2017-10718Recently it was discovered as a part of the research on IoT …
- CVE-2017-1072Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2017-10720Recently it was discovered as a part of the research on IoT …
- CVE-2017-10721Recently it was discovered as a part of the research on IoT …
- CVE-2017-10722Recently it was discovered as a part of the research on IoT …
- CVE-2017-10723Recently it was discovered as a part of the research on IoT …
- CVE-2017-10724Recently it was discovered as a part of the research on IoT …
Are you affected by CVE-2017-10719?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
