Home
HIGH: 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NHIGH: 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:NDefault status
unaffected
3.2.3.5.6
affected
Default status
unaffected
3.2.3.5.6
affected
Default status
unaffected
3.2.3.5.6
affected
Default status
unaffected
3.2.3.5.6
affected
Description
Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.
Problem types
CWE-306 Missing authentication for critical function
Product status
3.2.3.5.6
3.2.3.5.6
3.2.3.5.6
3.2.3.5.6
Credits
CISA discovered the PoCs (Proof of Concept) as authored by parsa rezaie khiabanloo.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-162-03
github.com/...p/csaf_files/OT/white/2026/icsa-26-162-03.json