LG.Smart.IP.Camera.Unauthenticated.Backup.File.Download

description-logoDescription

This indicates an attack attempt against an Arbitrary File Download vulnerability in multiple LG Smart IP Camera.
The vulnerability is due to insufficient sanitizing of user supplied inputs when handling a crafted HTTP request. Via a crafted HTTP request, it allows an unauthenticated remote attacker to download the vulnerable systems backup file that result in disclosure of information which could be used to further compromise the targeted system.

affected-products-logoAffected Products

LNB5110 with firmware from version 1310250 to version 1508190
LNB5320 with firmware from version 1310250 to version 1508190
LNB5320R with firmware from version 1310250 to version 1508190
LNB7210 with firmware from version 1310250 to version 1508190
LND3230R with firmware from version 1310250 to version 1508190
LND5110 with firmware from version 1310250 to version 1508190
LND5110R with firmware from version 1310250 to version 1508190
LND5220R with firmware from version 1310250 to version 1508190
LND7210 with firmware from version 1310250 to version 1508190
LND7210R with firmware from version 1310250 to version 1508190
LNU3230R with firmware from version 1310250 to version 1508190
LNU5110R with firmware from version 1310250 to version 1508190
LNU5320R with firmware from version 1310250 to version 1508190
LNU7210R with firmware from version 1310250 to version 1508190
LNV5110R with firmware from version 1310250 to version 1508190
LNV5320R with firmware from version 1310250 to version 1508190
LNV7210 with firmware from version 1310250 to version 1508190
LNV7210R with firmware from version 1310250 to version 1508190

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Currently we are unaware of any vendor supplied patch for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-10-01 14.697 Default_action:pass:drop
2019-08-08 14.666 Sig Added
2019-06-21 14.637

References

45394