Pricing
Contact
Login
Start Free Trial
Research Center
CVE-2021-40379 Research Center
topia vulnerability management banner 11.png

CVE-2021-40379

An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.

  • 7.5 high severity
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

  • 01/09/2021

Operating Systems 4

IP

IP70 Firmware

by Comprotech

1 Version

2 years ago

IP

IP570 Firmware

by Comprotech

1 Version

2 years ago

IP

IP60 Firmware

by Comprotech

1 Version

2 years ago

TN

TN540 Firmware

by Comprotech

1 Version

2 years ago

Vulnerability Categories 2

Improper Privilege Management
Missing Authorization

xTags 3

#easy_to_exploit
#known_vulnerability
#confidentiality_impact_if_exploited

Advisory Links 2

https://github.com/icekam/0day/blob/main/Compro-Technology-Camera-has-multiple-vulnerabilities.md
http://packetstormsecurity.com/files/164026/Compro-Technology-IP-Camera-RTSP-Stream-Disclosure.html
http://www.vicarius.io is owned and operated by Vicarius Ltd. (the “Company”). All information contained on the Website is purely for informational, and educational purposes and should be independently verified and confirmed. Vicarius does not accept any liability for any loss or damage whatsoever caused in reliance upon such information or services. No statements or information presented in any form by Vicarius is intended as fact, and you agree that you will not consider the statements or information presented on the Website as fact or as a guarantee of performance.

Related CVEs

Security Research Topics

By Paul Lighter
Jan 11, 2023

When the Target is Also the Threat

A software failure grounded thousands of flights today, raising a complicated question - how do you secure an unstable system? The answer has never been more urgent.
By Paul Lighter
Jan 06, 2023

The Uncomfortable Implications of the LastPass Attack

The recent attack on LastPass has people questioning if they can trust password managers. But there's a bigger issue lurking underneath - can you trust ANY security vendor?
By Paul Lighter
Nov 30, 2022

Online Casino Heist Shreds Confidence in Cybersecurity

Hackers recently swiped $300,000 from DraftKings accounts - and it was almost effortless. This attack will likely be forgotten by history. But it should be a wake-up call instead.
By Mohammad Hussam Alzeyyat
Nov 29, 2022

Ethernaut CTF - Vault Challenge

Here we are with the Vault challenge from Ethernaut CTF. We are going to be introduced to the NON Privacy on-chain and how we should not store secrets and critical information into variables even if we set the type of those variables as private. We will see how we can extract the values of those private variables.
By Mohammad Hussam Alzeyyat
Nov 18, 2022

DownUnderCTF 2022 Blockchain - Crypto Casino

In this blog, we are going to hack the casino contract of the DownUnderCTF 2022 challenges. There is a PRNG function that we are going to exploit it using a python script. Don't forget Hackers Gonna Hack!
last_chanse_04.png

Start Closing Security Gaps

  • Risk reduction from Day 1
  • Fast set-up and deployment
  • Unified platform
  • Full-featured 14-day trial
Get a Demo
Start Free Trial!

Have questions?

By submitting this form, you agree to be contacted about TOPIA and other Vicarius products.

Vicarius develops an autonomous vulnerability remediation platform to help security teams protect their assets against software exploitation. Consolidating vulnerability assessment, prioritization, and remediation, Vicarius strengthens cyber hygiene and proactively reduces risk.
We're hiring!

Support

support@vicarius.io

Sales

sales@vicarius.io

Marketing

info@vicarius.io
Product
Product Overview
Vulnerability Management
Patch Management
Patchless Protection
Auto Actions
Network Scanner
xTags
0-Day Detection
Solution
Solution Overview
Case Studies
Knowledge
Research Center
Apps & OS Patch Catalog
Videos
Articles
Docs
Company
About
Investors
Partners
Trust
Careers
Pricing
Pricing
Compare
TOPIA vs. Automox
TOPIA vs. ManageEngine
TOPIA vs. Rapid7
TOPIA vs. Tenable
TOPIA vs. Tanium
TOPIA vs. RMMs
TOPIA vs. Vulcan
TOPIA vs. PDQ
TOPIA vs. Qualys

Copyright © Vicarius. All rights reserved 2022. Privacy Policy and Terms of Use