Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rq7-2v73-8493

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it easier to enumerate users. However, only about 4 or 5 failed logins are allowed.

Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it easier to enumerate users. However, only about 4 or 5 failed logins are allowed.

EPSS

Процентиль: 55%
0.00329
Низкий

Связанные уязвимости

CVSS3: 5.3
nvd
около 6 лет назад

Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it easier to enumerate users. However, only about 4 or 5 failed logins are allowed.

EPSS

Процентиль: 55%
0.00329
Низкий