JVN#33706820
Multiple Panasonic Communications Co., Ltd. network cameras vulnerable to cross-site scripting
Overview
Multiple Panasonic Communications Co., Ltd. network cameras contain a cross-site scripting vulnerability.
Products Affected
- BL-C111 Ver.3.14R02 and earlier
- BL-C131 Ver.3.14R03 and earlier
- BB-HCM511 Ver.3.20R01 and earlier
- BB-HCM531 Ver.3.20R01 and earlier
- BB-HCM580 Ver.3.21R00 and earlier
- BB-HCM581 Ver.3.21R00 and earlier
- BB-HCM527 Ver.3.30R00 and earlier
- BB-HCM515 Ver.3.20R01 and earlier
For more information, refer to the vendor's website.
Description
Panasonic Communications Co., Ltd. network camera BL-C111/131 and BB-HCM511/531/580/581/527/515 error pages contain a cross-site scripting vulnerability.
Impact
An arbitrary script could be executed on the user's web browser.
Solution
Update the Software
Apply the latest updates provided by the vendor.
For more information, refer to the vendor's website.
Vendor Status
Vendor | Status | Last Update | Vendor Notes |
---|---|---|---|
Panasonic Communications Co., Ltd. | Vulnerable | 2008/07/31 |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Analyzed on 2008.07.31
Measures | Conditions | Severity |
---|---|---|
Access Required | Routed - can be attacked over the Internet using packets |
|
Authentication | None - anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | Simple - the user must be convinced to take a standard action that does not feel harmful to most users, such as click on a link or view a file |
|
Exploit Complexity | Low - little to no expertise and/or luck required to exploit (cross-site scripting) |
|
Credit
NetAgent Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory | |
CPNI Advisory | |
TRnotes | |
CVE |
CVE-2008-3482 |
JVN iPedia |
JVNDB-2008-000037 |