Latest MOBOTIX vulnerabilities #
MOBOTIX has disclosed several vulnerabilities in its P3 and Mx6 cameras.
CVE-2023-34873 has a CVSS score of 8.8 and allows an attacker to remotely execute code by exploiting improper input validation.
What is the impact? #
Successful exploitation of these vulnerabilities could allow an attacker to remotely execute code utilizing the tcpdump
functionality of the cameras since they do not properly validate input.
Are updates or workarounds available? #
MOBOTIX recommends applying the following updates to the respective camera models:
- Update P3 cameras to firmware version MX-V4.7.2.18 or later that includes a fixed version of the vulnerability.
- Update Mx6 cameras to firmware version MX-V5.2.0.61 or later that includes a fixed version of the vulnerability.
How to find potentially vulnerable MOBOTIX devices with runZero #
From the Asset Inventory, use the following query to locate systems running potentially vulnerable software:
hw:"MOBOTIX IP Camera"