Panasonic Sanyo CCTV Network Cameras versions 1.02-05 and 2.03-0x are vulnerable to CSRFs that can be exploited to allow an attacker to perform changes with administrator level privileges.
Solution:
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-04 | third party advisory us government resource |
https://archives.connect.panasonic.com/security/sanyo/index.html | vendor advisory |