Description
Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET request to /ConfigFile.ini or /config.xml URIs. This configuration file contains usernames and encrypted passwords (encrypted with a hardcoded key common to all devices). This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N, YM500L, YM800N_N2, YMF50B, YM800SV2, YM500L8, and YM200E10 firmware v3.2.2.2 and lower and possibly more vendors/models of IP camera.
INFO
Published Date :
2024-05-28T16:57:11.701Z
Last Modified :
2025-02-13T15:54:10.495Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2024-35341 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-35341.
| URL | Resource |
|---|---|
| https://willgu.es/pages/anpviz-ip-camera-vuln.html |
|