Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37h9-9838-7j9c

Опубликовано: 09 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6

Описание

Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream.  The credentials are being sent when a user decides to change his password in router's portal.

Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream.  The credentials are being sent when a user decides to change his password in router's portal.

EPSS

Процентиль: 31%
0.00113
Низкий

6 Medium

CVSS4

Дефекты

CWE-319

Связанные уязвимости

nvd
больше 1 года назад

Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream.  The credentials are being sent when a user decides to change his password in router's portal.

EPSS

Процентиль: 31%
0.00113
Низкий

6 Medium

CVSS4

Дефекты

CWE-319