Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37680


An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring system (Camera, Decoder and Encoder) and bellow allows attckers to remotely reboot the device via a crafted POST request to the endpoint /ptipupgrade.cgi. Security information ID hitachi-sec-2022-001 contains fixes for the issue.


Published

2022-08-29T23:15:08.687

Last Modified

2024-11-21T07:15:04.530

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hitachi hc-ip9100hd_firmware ≤ 1.07 Yes
Hardware hitachi hc-ip9100hd - No

References