Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg8p-w94g-466w

Опубликовано: 24 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to “/alarms/<ALARM_ID>/”, where the “MEDIA” parameter can take the value of “snapshot” or “video.mp4”. These media files contain images recorded by security cameras in response to triggered alerts.

Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to “/alarms/<ALARM_ID>/”, where the “MEDIA” parameter can take the value of “snapshot” or “video.mp4”. These media files contain images recorded by security cameras in response to triggered alerts.

EPSS

Процентиль: 19%
0.00061
Низкий

8.7 High

CVSS4

Дефекты

CWE-862

Связанные уязвимости

nvd
3 месяца назад

Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to “/alarms/<ALARM_ID>/<MEDIA>”, where the “MEDIA” parameter can take the value of “snapshot” or “video.mp4”. These media files contain images recorded by security cameras in response to triggered alerts.

EPSS

Процентиль: 19%
0.00061
Низкий

8.7 High

CVSS4

Дефекты

CWE-862