HIGH

CVE-2019-7315

CVSS v3

7.5

HIGH

EPSS Score

75.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x versions exist only for other Genie Access products).

Technical details

Published
6/17/2019

Frequently asked questions

What is CVE-2019-7315?

Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x versions exist only for other Genie Access products).

Is CVE-2019-7315 actively exploited?

Active exploitation of CVE-2019-7315 has not been confirmed. The EPSS score is 75.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-7315?

CVE-2019-7315 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2019-7315 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.