The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication parameters, an unauthenticated attacker can cause the RTSP service to enter a persistent authentication failure state, preventing legitimate clients from authenticating and leading to a denial of service.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-307 | |
| Metrics |
cvssV3_1
|
Tue, 28 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial of Service via Persistent Authentication Failure in MIPC252W RTSP Service | |
| Weaknesses | CWE-519 CWE-770 |
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mercury
Mercury mipc252w |
|
| Vendors & Products |
Mercury
Mercury mipc252w |
Mon, 27 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication parameters, an unauthenticated attacker can cause the RTSP service to enter a persistent authentication failure state, preventing legitimate clients from authenticating and leading to a denial of service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-28T12:52:39.002Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-35902
No data.
Status : Awaiting Analysis
Published: 2026-04-27T19:16:51.060
Modified: 2026-04-28T14:16:12.967
Link: CVE-2026-35902
No data.