VYPR
Unrated severityNVD Advisory· Published Jul 18, 2022· Updated Sep 17, 2024

Cellinx NVT – IP PTZ Camera Privilege Escalation

CVE-2022-30620

Description

On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.

Affected products

2
  • Vacron/Camerallm-fuzzy
  • Cellinx/Cellinx NVT - IP PTZ Camerav5
    Range: 3.2.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.