There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password).
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
https://www.bbge.org/file/exploit.py | broken link |
https://github.com/BBge/CVE-2018-17240/blob/main/exploit.py | exploit third party advisory |
https://github.com/BBge/CVE-2018-17240 | third party advisory |