| [Japanese] | 
| JVNDB-2017-000040 | 
| Multiple I-O DATA network camera products vulnerable to OS command injection | 
|
| 
 
Multiple network camera products provided by I-O DATA DEVICE, INC. contain an OS command injection vulnerability.
 Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported respective vulnerabilities to IPA.
 JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V3 Severity:Base Metrics 8.8 (High) [IPA Score]
 
    Attack Vector: Adjacent NetworkAttack Complexity: LowPrivileges Required: NoneUser Interaction: NoneScope: UnchangedConfidentiality Impact: HighIntegrity Impact: HighAvailability Impact: High 
  CVSS V2 Severity:Base Metrics 5.8 (Medium) [IPA Score]
 
    Access Vector: Adjacent NetworkAccess Complexity: LowAuthentication: NoneConfidentiality Impact: PartialIntegrity Impact: PartialAvailability Impact: Partial 
  
 | 
|
| 
 
	
 | 
| 
 
	I-O DATA DEVICE, INC.
	
		TS-PTCAM firmware version 1.18 and earlierTS-PTCAM/POE firmware version 1.18 and earlierTS-WLC2 firmware version 1.18 and earlierTS-WLCE firmware version 1.18 and earlierTS-WPTCAM firmware version 1.18 and earlierTS-WPTCAM2 firmware version 1.00TS-WRLC firmware version 1.17 and earlier | 
| 
 
	
 | 
|
| 
 
A remote unauthenticated attacker may execute an arbitrary OS command on the product.
 | 
|
| 
 
[Update the Firmware]Apply the appropriate firmware update provided by the developer.
 | 
|
| 
 
	I-O DATA DEVICE, INC.
	
 | 
|
| 
 
	OS Command Injection(CWE-78) [IPA Evaluation] | 
|
| 
 
	CVE-2017-2112  | 
|
| 
 
	JVN : JVN#46830433 National Vulnerability Database (NVD) : CVE-2017-2112  | 
|
| 
 
	[2017/03/02]Web page was published
 [2017/03/08]
 Affected Products : Product was added
 [2017/06/06]
 References : Content was added
 
 |