Security Advisory

CVE-2017-14743

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-09-26 06:00:00
Last updated 2024-09-17 02:16:06
Assigner mitre
State PUBLISHED

Description

Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.