CVE-2022-30620
EUVD-2022-5245118.07.2022, 13:15
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cellinx | cellinx_nvt_-_ip_ptz_camera_firmware | 3.2.0 |
| cellinx | cellinx_nvt_-_ip_ptz_camera_firmware | 3.2.1 |
𝑥
= Vulnerable software versions