HTTP: Wireless IP Camera P2P WIFICAM Camera Authentication Bypass

This signature detects attempts to exploit a known vulnerability against Wireless IP Camera. Attackers could bypass security restrictions to gain unauthorized access to user accounts.

Extended Description

On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.

Short Name
HTTP:MISC:WIFICAM-AUTH-BYPASS
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Authentication Bypass CVE-2017-8225 Camera IP P2P WIFICAM Wireless
Release Date
10/24/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3377
False Positive
Unknown
CVSS Score

7.5

Found a potential security threat?