← Back to home
ICSA-23-304-03  ·  Published 2023-10-31  ·  View on CISA ICS-CERT ↗

Zavio IP Camera

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of these vulnerabilities could allow remote code execution.

Remediations

  • The affected products are end-of-life and have been identified to contain many insecurities. The vendor, Zavio, is no longer actively in business and therefore development for firmware fixes, mitigations, and updates are not available and will not become available. CISA recommends users discontinue use of the product.

Affected Vendors

Zavio

Affected Products (11)

Zavio · CF7500 M2.1.6.05
Zavio · CF7300 M2.1.6.05
Zavio · CF7201 M2.1.6.05
Zavio · CF7501 M2.1.6.05
Zavio · CB3211 M2.1.6.05
Zavio · CB3212 M2.1.6.05
Zavio · CB5220 M2.1.6.05
Zavio · CB6231 M2.1.6.05
Zavio · B8520 M2.1.6.05
Zavio · B8220 M2.1.6.05
Zavio · CD321 M2.1.6.05

Affected Sectors

Multiple

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more