Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2017-8228

8.8 · HIGH
Published Jul 3, 2019 amcrest CWE-264 EPSS 2.60% (84th pctl)

Overview

CVE-2017-8228 is a high-severity vulnerability affecting amcrest ipm-721s_firmware. It was published on July 3, 2019 and has a CVSS 3.0 base score of 8.8 (HIGH).

This vulnerability has a CVSS 3.0 base score of 8.8, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough verification when allowing the user to add a new camera to the user's account to ensure that the user actually owns the camera other than knowing the serial number of the camera. This can allow an attacker who knows the serial number to easily add another user's camera to an attacker's cloud account and control it completely. This is possible in case of any camera that is currently not a part of an Amcrest cloud account or has been removed from the user's cloud account. Also, another requirement for a successful attack is that the user should have rebooted the camera in the last two hours. However, both of these conditions are very likely for new cameras that are sold over the Internet at many ecommerce websites or vendors that sell the Amcrest products. The successful attack results in an attacker being able to completely control the camera

Remediation

Check the references section for vendor advisories and patches from amcrest. Update ipm-721s_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
amcrest ipm-721s_firmware 0 Affected

Frequently Asked Questions

What is CVE-2017-8228?

CVE-2017-8228 is a high-severity vulnerability affecting amcrest ipm-721s_firmware. It was published on July 3, 2019 and has a CVSS 3.0 base score of 8.8 (HIGH).

How severe is CVE-2017-8228?

This vulnerability has a CVSS 3.0 base score of 8.8, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2017-8228?

Check the references section for vendor advisories and patches from amcrest. Update ipm-721s_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2017-8228?

CyberStrike's AI-powered security agents can automatically detect CVE-2017-8228 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.