Vulnerabilities > Cohuhd > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-11-22 CVE-2017-8864 Protection Mechanism Failure vulnerability in Cohuhd 3960Hd Firmware
Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent to the camera and cause malfunction or code execution, as demonstrated by a client-side "if (!passwordsAreEqual())" test.
network
low complexity
cohuhd CWE-693
critical
9.8
2017-11-22 CVE-2017-8862 Unrestricted Upload of File with Dangerous Type vulnerability in Cohuhd 3960Hd Firmware
The webupgrade function on the Cohu 3960HD does not verify the firmware upgrade files or process, allowing an attacker to upload a specially crafted postinstall.sh file that will be executed with "root" privileges.
network
low complexity
cohuhd CWE-434
critical
9.8
2017-11-22 CVE-2017-8861 Improper Authentication vulnerability in Cohuhd 3960Hd Firmware
Missing authentication for the remote configuration port 1236/tcp on the Cohu 3960HD allows an attacker to change configuration parameters such as IP address and username/password via specially crafted XML SOAP packets.
network
low complexity
cohuhd CWE-287
critical
9.8