Cleartext storage of sensitive information in AVTECH Corporation products - #VU48216

 

Cleartext storage of sensitive information in AVTECH Corporation products - #VU48216

Published: November 9, 2020


Vulnerability identifier: #VU48216
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to software stores passwords of all device users clear text. A local user can view contents of the file and recover credentials of other device users.



Affected software

IP camera
NVR
DVR

Remediation

Install updates from vendor's website.


External References

Related Security Bulletins