Unauthorized Access Control Vulnerability in Uniview IP Camera
Published Sep 19, 2023
9.8
CRITICALCVSS 3.1
EPSS 1.25%
Description
The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.
Successful exploitation of this vulnerability could allow the attacker to gain complete control of the targeted device.
Affected products
-
- Version CIPC-B2303.X.X.XXXXXXStatusaffectedConstraints<=CIPC-B2303.2.8.230105
- Version DIPC-B1213.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1213.6.5.230215
- Version DIPC-B1216.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1216.5.7.230109
- Version DIPC-B1219.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1219.2.67.221019
- Version DIPC-B1221.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1221.3.5.221202
- Version DIPC-B1222.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1222.3.8.230223
- Version DIPC-B1223.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1223.3.3.221123
- Version DIPC-B1225.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1225.3.3.221123
- Version DIPC-B1226.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1226.3.6.230105
- Version DIPC-B1228.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1228.2.65.230207
- Version DIPC-B1229.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1229.1.67.230104
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Uniview | Uniview IP Camera IPC322LB-SF28-A | unaffected |
|
Configuration 1
- ≤ cipc-b2303.2.8.230105
Running on/with
- n/a
Configuration 2
- ≤ dipc-b1213.6.5.230215
Running on/with
- n/a
Configuration 3
- ≤ dipc-b1216.5.7.230109
Running on/with
- n/a
Configuration 4
- ≤ dipc-b1221.3.5.221202
Running on/with
- n/a
Configuration 5
- ≤ dipc-b1222.3.8.230223
Running on/with
- n/a
Configuration 6
- ≤ dipc-b1225.3.3.221123
Running on/with
- n/a
Configuration 7
- ≤ dipc-b1226.3.6.230105
Running on/with
- n/a
Configuration 8
- ≤ dipc-b1219.2.67.221019
Running on/with
- n/a
Configuration 9
- ≤ dipc-b1223.3.3.221123
Running on/with
- n/a
Configuration 10
- ≤ dipc-b1228.2.65.230207
Running on/with
- n/a
Configuration 11
- ≤ dipc-b1229.1.67.230104
Running on/with
- n/a
-
- Version CIPC-B2303.X.X.XXXXXXStatusaffectedConstraints<=CIPC-B2303.2.8.230105
- Version DIPC-B1213.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1213.6.5.230215
- Version DIPC-B1216.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1216.5.7.230109
- Version DIPC-B1219.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1219.2.67.221019 affected
- Version DIPC-B1221.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1221.3.5.221202
- Version DIPC-B1222.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1222.3.8.230223
- Version DIPC-B1223.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1223.3.3.221123
- Version DIPC-B1225.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1225.3.3.221123
- Version DIPC-B1226.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1226.3.6.230105
- Version DIPC-B1228.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1228.2.65.230207
- Version DIPC-B1229.X.X.XXXXXXStatusaffectedConstraints<=DIPC-B1229.1.67.230104
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Uniview | IP Camera Ipc322lb-Sf28-A | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
https://global.uniview.com/About_Us/Security/Notice/202309/976482_140493_0.htm https://global.uniview.com/About_Us/Security/Notice/202309/976482_140493_0.htm
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Sep 25, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.25% (0.01251) | 68.38th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.17% (0.01172) | 63.25th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.56% (0.00560) | 65.63th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.63% (0.01628) | 70.36th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.54% (0.00542) | 65.71th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.30% (0.00297) | 70.17th | v3 (v2023.03.01) |
| Sep 22, 2023 | 0.08% (0.00078) | 32.21th | v3 (v2023.03.01) |
| Sep 20, 2023 | 0.05% (0.00048) | 15.09th | v3 (v2023.03.01) |
References (2)
- https://global.uniview.com/About_Us/Security/Notice/202309/976482_140493_0.htm vendor-advisoryVendor Advisory
- https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0270 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://global.uniview.com/About_Us/Security/Notice/202309/976482_140493_0.htm | vendor-advisoryVendor Advisory | |
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0270 | Third Party Advisory |
Change history (0)
No recorded changes yet.