Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-12553

Опубликовано: 13 дек. 2024
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used.

The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25394.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:geovision:gv-asmanager:6.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00162
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
github
около 1 года назад

GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used. The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25394.

CVSS3: 6.5
fstec
около 1 года назад

Уязвимость программного обеспечения для управления системой контроля доступа Geovision GV-ASManager, связанная с отсутствием процедуры авторизации, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 37%
0.00162
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862