First published: Sat May 14 2005(Updated: )
GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Geovision Digital Surveillance System | =6.1 | |
Geovision Digital Surveillance System | =6.0.4 | |
Geovision Digital Surveillance System | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1552 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
To mitigate CVE-2005-1552, ensure that JPEG images are not accessible without proper authorization and consider disabling the creation of JPEG images if possible.
CVE-2005-1552 affects GeoVision Digital Video Surveillance System versions 6.0.4, 6.1, and 7.0.
CVE-2005-1552 exposes an attack vector where remote attackers can gain access to sensitive images via direct requests.
Yes, there are known exploits for CVE-2005-1552 that allow remote attackers to access unprotected JPEG images.