SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, SNC-EM520, SNC-EM521, SNC-ZB550, SNC-ZM550, SNC-ZM551, SNC-EP550, SNC-EP580, SNC-ER550, SNC-ER550C, SNC-ER580, SNC-ER585, SNC-ER585H, SNC-ZP550, SNC-ZR550, SNC-EP520, SNC-EP521, SNC-ER520, SNC-ER521, SNC-ER521C network cameras with firmware before Ver.1.86.00 and SONY SNC-CX600, SNC-CX600W, SNC-EB600, SNC-EB600B, SNC-EB602R, SNC-EB630, SNC-EB630B, SNC-EB632R, SNC-EM600, SNC-EM601, SNC-EM602R, SNC-EM602RC, SNC-EM630, SNC-EM631, SNC-EM632R, SNC-EM632RC, SNC-VB600, SNC-VB600B, SNC-VB600B5, SNC-VB630, SNC-VB6305, SNC-VB6307, SNC-VB632D, SNC-VB635, SNC-VM600, SNC-VM600B, SNC-VM600B5, SNC-VM601, SNC-VM601B, SNC-VM602R, SNC-VM630, SNC-VM6305, SNC-VM6307, SNC-VM631, SNC-VM632R, SNC-WR600, SNC-WR602, SNC-WR602C, SNC-WR630, SNC-WR632, SNC-WR632C, SNC-XM631, SNC-XM632, SNC-XM636, SNC-XM637, SNC-VB600L, SNC-VM600L, SNC-XM631L, SNC-WR602CL network cameras with firmware before Ver.2.7.2 are prone to sensitive information disclosure. This may allow an attacker on the same local network segment to login to the device with administrative privileges and perform operations on the device.
References
Link | Resource |
---|---|
https://jvn.jp/en/vu/JVNVU96435227/index.html | Third Party Advisory VDB Entry |
https://www.sony.co.uk/pro/article/sony-new-firmware-for-network-cameras | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
No history.
Information
Published : 2017-04-13 17:59
Updated : 2024-02-04 19:11
NVD link : CVE-2016-7834
Mitre link : CVE-2016-7834
CVE.ORG link : CVE-2016-7834
JSON object : View
Products Affected
sony
- snc-em631
- snc-vb6305
- snc-vm6305
- snc-vm632r
- snc-em632r
- snc-vm600
- snc-em632rc
- snc-dh120
- snc-er550
- snc-em602r
- snc-vb630
- snc-em521
- snc-er520
- snc-wr632c
- snc-zr550
- snc-er585h
- snc-cx600
- snc-wr602c
- snc-er580
- snc-vb600
- snc-dh120t
- snc-xm631
- snc-vb6307
- snc-wr602
- snc-zp550
- snc-ch260
- snc-eb520
- snc-xm637
- snc-zm551
- snc-er550c
- snc-dh160
- snc-eb630b
- snc-vb600b5
- snc-er521c
- snc-eb602r
- snc-wr630
- snc-xm631l
- snc-ch160
- snc-wr600
- snc-ch220
- snc-dh260
- snc-em601
- snc-vm6307
- snc-xm632
- snc-vm600b5
- snc-vb600b
- snc-eb630
- snc-em630
- snc-wr632
- snc-eb600
- snc-vm602r
- snc-em520
- snc-dh220
- snc-ep520
- snc-eb600b
- snc-vm630
- snc-zm550
- snc-ep521
- snc-cx600w
- snc-vm601
- snc-vb632d
- snc-em602rc
- snc-vb600l
- snc-er521
- snc-vb635
- snc-xm636
- snc-vm631
- snc-ep580
- snc-vm600b
- snc-vm600l
- snc-vm601b
- snc-ch120
- snc-er585
- snc-dh220t
- snc_series_firmware
- snc-ch115
- snc-ep550
- snc-eb632r
- snc-wr602cl
- snc-em600
- snc-zb550
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor