CVE-2019-11064
29.08.2019, 01:15
A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrators account and password in plain text via cgibin/ExportSettings.cgi?Export=1 without any authentication.Enginsight
Vendor | Product | Version |
---|---|---|
androvideo | vd_1_firmware | 𝑥 ≤ 230 |
geovision | gv-vr360_firmware | 𝑥 ≤ 1.10 |
geovision | gv-vd8700_firmware | 𝑥 ≤ 1.01 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
References