Improper validation of certificate with host mismatch in AVTECH Corporation products - #VU48227
Published: November 9, 2020
IP camera
DVR
NVR
AVTECH Corporation
Description
The vulnerability allows a remote attacker to perform a MitM attack.
The vulnerability exists due to software does not verify identity of the supplied HTTPS certificate in SyncCloudAccount.sh, QueryFromClient.sh and SyncPermit.sh scripts. A remote attacker can perform MitM attack and compromise the device by supplying a malicious firmware update.