English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Edimax IC-3030iWn Network Camera Password Disclosure Vulnerability


Secunia ID

SA49524

Release Date

20 Jun 2012

Criticality

Less Critical

Solution Status

Unpatched

Where

From local network

Impact
Exposure of sensitive information

Vulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote.

Description

A vulnerability has been reported in Edimax IC-3030iWn Network Camera, which can be exploited by malicious people to disclose sensitive information.

The vulnerability is caused due to an improper authentication mechanism, which sends credentials to the client side for authentication and can be exploited to disclose e.g. the administrative password.

Solution

Restrict access to the device to trusted hosts only.

Reported by

y3dips

Original Advisory

http://packetstormsecurity.org/files/113553/Edimax-IC-3030iWn-Authentication-Bypass.html