[Japanese]
|
JVNDB-2008-000037
|
Multiple Panasonic Communications Co., Ltd. network cameras vulnerable to cross-site scripting
|
Multiple Panasonic Communications Co., Ltd. network cameras contain a cross-site scripting vulnerability.
Panasonic Communications Co., Ltd. network camera BL-C111/131 and BB-HCM511/531/580/581/527/515 error pages contain a cross-site scripting vulnerability.
NetAgent Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 4.3 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
Panasonic Communications Co., Ltd
- BB-HCM511 Ver.3.20R01 and earlier
- BB-HCM515 Ver.3.20R01 and earlier
- BB-HCM527 Ver.3.30R00 and earlier
- BB-HCM531 Ver.3.20R01 and earlier
- BB-HCM580 Ver.3.21R00 and earlier
- BB-HCM581 Ver.3.21R00 and earlier
- BL-C111 Ver.3.14R02 and earlier
- BL-C131 Ver.3.14R03 and earlier
|
|
An arbitrary script could be executed on the user's web browser.
|
[Update the Software]
Apply the latest updates provided by the vendor.
For more information, refer to the vendor's website.
|
Panasonic Communications Co., Ltd
|
- Cross-site Scripting(CWE-79) [IPA Evaluation]
|
- CVE-2008-3482
|
- JVN : JVN#33706820
- National Vulnerability Database (NVD) : CVE-2008-3482
- Secunia Advisory : SA31304
- FrSIRT Advisories : FrSIRT/ADV-2008-2257
- JVN iPedia (Japanese) : JVNDB-2008-000037
|
- [2008/08/04]
Web page published
|