SSD provides vulnerability details and proof of concept for CVE-2023-0773 (9.1 critical, disclosed 11 September 2023 by Uniview) authentication bypass in IPC2322LB network camera. "If this is combined with a CLI escape, the Uniview device’s security can be completely compromised." πŸ”— https://ssd-disclosure.com/ssd-advisory-uniview-ipc2322lb-auth-bypass-and-cli-escape/

H/T @buherator

#CVE_2023_0773 #Uniview #vulnerability #proofofconcept

SSD Advisory - Uniview IPC2322LB Auth Bypass and CLI escape - SSD Secure Disclosure

Summary The Uniview IPC2322LB processes authentication requests allows remote attackers to bypass the authentication process and gain unauthorized access. If this is combined with a CLI escape, the Uniview device’s security can be completely compromised. Credit Yoseop Kim working for SSD Labs Korea Vendor Response The vendor has released an advisory that addresses this issue: … SSD Advisory – Uniview IPC2322LB Auth Bypass and CLI escape Read More Β»

SSD Secure Disclosure