The server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Axis M1125) to see FTP credentials in a cleartext HTTP traffic. These can be used for FTP access to the server.
2022-07-21T16:15:08.987
2024-11-21T06:58:04.857
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | citilog | citilog | 8.0 | Yes |
Hardware | axis | m1125 | - | No |