CVE-2017-2111

HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier may allow a remote attackers to display false information.
CRLF Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
jpcertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
iodatats-ptcam\/poe_firmware
𝑥
≤ 1.18
iodatats-ptcam_firmware
𝑥
≤ 1.18
iodatats-wrlc_firmware
𝑥
≤ 1.17
iodatats-wlc2_firmware
𝑥
≤ 1.18
iodatats-wlce_firmware
𝑥
≤ 1.18
iodatats-wptcam2_firmware
1.00
iodatats-wptcam_firmware
𝑥
≤ 1.18
𝑥
= Vulnerable software versions