VDB
CVE-2017-3185
CVE-2017-3185
PUBLISHED
CVSS 5 MEDIUM
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.
EPSS 1.71% · 82.7th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
1.71%
82.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ACTi Corporation | ACTi D, B, I, and E series cameras | A1D-500-V6.11.31-AC |
| acti | camera_firmware | a1d-500-v6.11.31-ac |
Timeline
- Mar 7, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://twitter.com/hack3rsca/status/839599437907386368 url
- 96720 vdb
- https://twitter.com/Hfuhs/status/839252357221330944 url
- VU#355151 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-3185 advisory