Executive brief
MotionEye is a popular open-source surveillance software that manages IP cameras and video monitoring. This vulnerability allows unauthenticated attackers to retrieve sensitive configuration information by making a simple web request when the system lacks proper password protection, potentially exposing camera details and system settings.
Technical details
MotionEye versions 0.42.1 and earlier contain an information disclosure vulnerability (CWE-200) in the /config/list endpoint. The vulnerability allows unauthenticated attackers to access sensitive configuration data via a GET request when no regular user password is configured. The attack requires no authentication and is trivial to execute over the network. Exploitation exposes system configuration details that could aid further reconnaissance. The vulnerability is fixed in version 0.43.1b1.
Affected products
- MotionEye Project MotionEye 0.42.1 and earlier
Timeline
- 2022-03-25: disclosed
- 2022: patched: Fixed in version 0.43.1b1