Description

Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP GET request to the /playback/ URI. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N, YM500L, YM800N_N2, YMF50B, YM800SV2, YM500L8, and YM200E10 (IP Cameras) firmware v3.2.2.2 and lower and possibly more vendors/models of IP camera.

INFO

Published Date :

2024-05-28T16:46:52.274Z

Last Modified :

2025-02-13T15:54:11.605Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-35343 vulnerability.

Vendors Products
Anpviz
  • Ipc-b850 Firmware
  • Ipc-d250 Firmware
  • Ipc-d260 Firmware
  • Ipc-d280 Firmware
  • Ipc-d3150 Firmware
  • Ipc-d3180 Firmware
  • Ipc-d350 Firmware
  • Ipc-d380 Firmware
  • Ipc-d4250 Firmware
  • Ipc-d850 Firmware
  • Ipc-d880 Firmware
  • Mc800n Firmware
  • Ym200e10 Firmware
  • Ym500l8 Firmware
  • Ym800n N2 Firmware
  • Ym800sv2 Firmware
  • Ymf50b Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-35343.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact