CVE-2017-7648

EUVD-2017-16653
Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
foscamc1
*
foscamc1_lite
*
foscamc2
*
foscamfi9800xe
*
foscamfi9826p
*
foscamfi9828p
*
foscamfi9851p
*
foscamfi9853ep
*
foscamfi9901ep
*
foscamfi9903p
*
foscamfi9928p
*
foscamr2
*
𝑥
= Vulnerable software versions