Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-7057

Опубликовано: 14 янв. 2020
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it easier to enumerate users. However, only about 4 or 5 failed logins are allowed.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:hikvision:ds-7204hghi-f1_firmware:4.0.1:180903:*:*:*:*:*:*
cpe:2.3:h:hikvision:ds-7204hghi-f1:-:*:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.00329
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-307

Связанные уязвимости

github
больше 3 лет назад

Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it easier to enumerate users. However, only about 4 or 5 failed logins are allowed.

EPSS

Процентиль: 55%
0.00329
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-307