Geutebrück G-Cam E2 命令注入漏洞
CVE编号
CVE-2021-33544利用情况
暂无补丁情况
N/A披露时间
2021-09-17漏洞描述
Geutebrück G-Cam E2是manualslib的一个摄像机。 Geutebrück G-Cam E2 存在命令注入漏洞,该漏洞源于受影响的产品容易受到命令注入的攻击。这可能允许攻击者可利用该漏洞远程执行任意代码。 受影响的产品及版本:E2 Series cameras – G-CAM:1.12.0.27版本及之前版本、1.12.13.2版本、1.12.14.5版本;Encoder G-Code:1.12.0.27版本及之前版本、1.12.13.2版本、1.12.14.5版本。解决建议
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03
参考链接 |
|
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03 | |
https://www.auscert.org.au/bulletins/ESB-2021.2550 | |
https://www.randorisec.fr/fr/udp-technology-ip-camera-vulnerabilities/ |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ebc-2110_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ebc-2110_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ebc-2110_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ebc-2111_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ebc-2111_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ebc-2111_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ebc-2112_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ebc-2112_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ebc-2112_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_efd-2241_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_efd-2241_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_efd-2241_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_efd-2250_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_efd-2250_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_efd-2250_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_efd-2251_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_efd-2251_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_efd-2251_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2230_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2230_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2230_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2239_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2239_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2239_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2240_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2240_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2240_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2249_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2249_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ethc-2249_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ewpc-2270_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ewpc-2270_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ewpc-2270_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ewpc-2271_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ewpc-2271_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ewpc-2271_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ewpc-2275_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ewpc-2275_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-cam_ewpc-2275_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-code_eec-2400_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-code_eec-2400_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-code_eec-2400_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-code_een-2010_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-code_een-2010_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-code_een-2010_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-code_een-2040_firmware | * | Up to (including) 1.12.0.27 | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-code_een-2040_firmware | 1.12.13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | geutebrueck | g-code_een-2040_firmware | 1.12.14.5 | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_ebc-2110 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_ebc-2111 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_ebc-2112 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_efd-2241 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_efd-2250 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_efd-2251 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_ethc-2230 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_ethc-2239 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_ethc-2240 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_ethc-2249 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_ewpc-2270 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_ewpc-2271 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-cam_ewpc-2275 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-code_eec-2400 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-code_een-2010 | * | - | |||||
运行在以下环境 | |||||||||
硬件 | geutebrueck | g-code_een-2040 | * | - | |||||
- 攻击路径 网络
- 攻击复杂度 低
- 权限要求 高
- 影响范围 未更改
- 用户交互 无
- 可用性 高
- 保密性 高
- 完整性 高
CWE-ID | 漏洞类型 |
CWE-77 | 在命令中使用的特殊元素转义处理不恰当(命令注入) |
CWE-78 | OS命令中使用的特殊元素转义处理不恰当(OS命令注入) |
Exp相关链接

版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论