CVE-2018-17879

CRITICALCVSS 9.8/10EPSS 21.85%

Last modified

CVE-2018-17879 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. EPSS estimates a 21.85% chance of exploitation in the next 30 days.

Description

An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scripts.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
21.85%

97.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AbusTvip 10000 FirmwareAll versions
AbusTvip 10001 FirmwareAll versions
AbusTvip 10005 FirmwareAll versions
AbusTvip 10005a FirmwareAll versions
AbusTvip 10005b FirmwareAll versions
AbusTvip 10050 FirmwareAll versions
AbusTvip 10051 FirmwareAll versions
AbusTvip 10055a FirmwareAll versions
AbusTvip 10055b FirmwareAll versions
AbusTvip 10500 FirmwareAll versions
AbusTvip 10550 FirmwareAll versions
AbusTvip 11000 FirmwareAll versions
AbusTvip 11050 FirmwareAll versions
AbusTvip 11500 FirmwareAll versions
AbusTvip 11501 FirmwareAll versions
AbusTvip 11502 FirmwareAll versions
AbusTvip 11550 FirmwareAll versions
AbusTvip 11551 FirmwareAll versions
AbusTvip 11552 FirmwareAll versions
AbusTvip 20000 FirmwareAll versions
AbusTvip 20050 FirmwareAll versions
AbusTvip 20500 FirmwareAll versions
AbusTvip 20550 FirmwareAll versions
AbusTvip 21000 FirmwareAll versions
AbusTvip 21050 FirmwareAll versions
AbusTvip 21500 FirmwareAll versions
AbusTvip 21501 FirmwareAll versions
AbusTvip 21502 FirmwareAll versions
AbusTvip 21550 FirmwareAll versions
AbusTvip 21551 FirmwareAll versions
AbusTvip 21552 FirmwareAll versions
AbusTvip 22500 FirmwareAll versions
AbusTvip 31000 FirmwareAll versions
AbusTvip 31001 FirmwareAll versions
AbusTvip 31050 FirmwareAll versions
AbusTvip 31500 FirmwareAll versions
AbusTvip 31501 FirmwareAll versions
AbusTvip 31550 FirmwareAll versions
AbusTvip 31551 FirmwareAll versions
AbusTvip 32500 FirmwareAll versions
AbusTvip 51500 FirmwareAll versions
AbusTvip 51550 FirmwareAll versions
AbusTvip 71500 FirmwareAll versions
AbusTvip 71501 FirmwareAll versions
AbusTvip 71550 FirmwareAll versions
AbusTvip 71551 FirmwareAll versions
AbusTvip 72500 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-17879?
An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scripts.
How severe is CVE-2018-17879?
CVE-2018-17879 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 21.85% probability of exploitation in the next 30 days.
How do I fix CVE-2018-17879?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-17879?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST