Session Fixation in AVTECH Corporation products - #VU48225
Published: November 9, 2020
IP camera
DVR
NVR
AVTECH Corporation
Description
The vulnerability allows a remote attacker to perform session fixation attacks.
The vulnerability exists due to application is using base64-encoded username and password as the Cookie value instead of randomly generated session identifier. A remote attacker can obtain or brute-force such session token and gain unauthorized access to the device.