ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. A remote attacker can take complete control of a device using default admin credentials.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HActi Camera Firmware
OSActia1d-500-v6.11.31-ac
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2017-3184CRITICAL9.8PL ✓same product
ACTi Camera Firmware — nieautoryzowany dostęp do strony factory reset
CVE-2017-3185CRITICAL9.8PL ✓same product
ACTi Camera Firmware — dane uwierzytelniające w żądaniach GET
CVE-2020-15956HIGH7.5same vendor
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigge...
CVE-2007-4582HIGH7.5same vendor
Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ...
CVE-2007-4583MEDIUM5.0same vendor
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1...