CVE-2021-33552: fallo de gravedad alta en Geutebrück E2 Series
UDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
Publicada el · Actualizada el
70Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 7.2epss 49%
de la publicación al arma0 días
Publicada en NVD13 sept
metasploit8 jul
VulnCheck+756d
probabilidad de explotación
49%top 1% de las CVE
explotación observada
síVulnCheck
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEs relacionadas — Geutebrück E2 Series
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-33544HIGHUDP Technology/Geutebrück camera devices: command injection leading to RCEEPSS 95.3%CVE-2021-33543CRITICALUDP Technology/Geutebrück camera devices: Authentication BypassEPSS 81.3%CVE-2021-33549HIGHUDP Technology/Geutebrück camera devices: Buffer overflow in action parameter leading to RCEEPSS 66.2%CVE-2021-33554HIGHUDP Technology/Geutebrück camera devices: Command injection in appfile.filename parameter leading to RCEEPSS 57.0%CVE-2021-33550HIGHUDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCEEPSS 57.0%CVE-2021-33548HIGHUDP Technology/Geutebrück camera devices: Command injection in preserve parameter leading to RCEEPSS 57.0%