Improper Authentication in AVTECH Corporation products - #VU48223

 

Improper Authentication in AVTECH Corporation products - #VU48223

Published: November 9, 2020


Vulnerability identifier: #VU48223
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to application allows unauthenticated requests to scripts, if request URI contains ".cab" or "/nobody" strings.  A remote non-authenticated attacker can append to URL ".cab" or "/nobody" string, bypass authentication process and gain unauthorized access to the application, as well as download source code of scripts on the device.


Affected software

IP camera
DVR
NVR

Remediation

Install updates from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins