Junglewise Threat Intelligence

CVE-2022-25568: PYSEC-2022-43141 - MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerabilit

CVE-2022-25568 · Severity: low · CVSS 3.1 · Published 2022-03-24

Technologies: motioneye (PyPI). Vendors: PyPI.

Executive brief

MotionEye is a popular open-source surveillance software that manages IP cameras and video monitoring. This vulnerability allows unauthenticated attackers to retrieve sensitive configuration information by making a simple web request when the system lacks proper password protection, potentially exposing camera details and system settings.

Technical details

MotionEye versions 0.42.1 and earlier contain an information disclosure vulnerability (CWE-200) in the /config/list endpoint. The vulnerability allows unauthenticated attackers to access sensitive configuration data via a GET request when no regular user password is configured. The attack requires no authentication and is trivial to execute over the network. Exploitation exposes system configuration details that could aid further reconnaissance. The vulnerability is fixed in version 0.43.1b1.

Affected products

  • MotionEye Project MotionEye 0.42.1 and earlier

Timeline

  • 2022-03-25: disclosed
  • 2022: patched: Fixed in version 0.43.1b1

References

Related threats