Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4xh-gcmh-gc28

Опубликовано: 01 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and NVRs via Machine.cgi?action=get_capability. Sensitive internal device information such as firmware version, MAC address, and codec support can be accessed without authentication.

An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and NVRs via Machine.cgi?action=get_capability. Sensitive internal device information such as firmware version, MAC address, and codec support can be accessed without authentication.

6.9 Medium

CVSS4

Дефекты

CWE-200

Связанные уязвимости

nvd
7 месяцев назад

Rejected reason: An unauthenticated endpoint that exposes firmware version, MAC address, and supported codecs is not indicative of a security boundary being crossed, as this metadata is not inherently sensitive and commonly used for legitimate fingerprinting and discovery.

CVSS3: 5.3
fstec
7 месяцев назад

Уязвимость компонента Machine.cgi?action=get_capability микропрограммного обеспечения IP-камер, цифровых и сетевых видеорегистраторов Avtech, позволяющая нарушителю получить несанкционированный доступ к конфиденциальной информации

6.9 Medium

CVSS4

Дефекты

CWE-200