Multiple product vulnerabilities were identified in Moxa’s VPort 06EC-2V Series IP Cameras. In response to this, Moxa has developed related solutions to address these vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
NULL Pointer Dereference CVE-2021-25845 |
The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions. |
| 2 |
Integer Underflow CVE-2021-25846, CVE-2021-25849, |
An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable. |
| 3 |
Out-of-Bounds Read CVE-2021-25847, CVE-2021-25848 |
An attacker may be able to edit the element of an HTTP request to read sensitive information or even cause the device to become unavailable. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/vport-06ec-2v-series-ip-cameras-vulnerabilities