CVE-2020-7057: Medium severity Hikvision Ds-7204hghi-f1 Firmware vulnerability
Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version sends a different response for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists, which might make it easier to enumerate users. However, only about 4 or 5 failed logins are allowed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7057?
CVE-2020-7057 is a vulnerability found in the Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version that allows for easier enumeration of user accounts.
What is the severity of CVE-2020-7057?
CVE-2020-7057 has a severity score of 5.3, which is categorized as medium.
How does CVE-2020-7057 affect Hikvision DVR DS-7204HGHI-F1 firmware 4.0.1-180903?
CVE-2020-7057 affects Hikvision DVR DS-7204HGHI-F1 firmware 4.0.1-180903 by allowing for easier enumeration of user accounts through different responses for failed login attempts.
How many failed logins are allowed in Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version?
Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 Web Version allows for about 4 or 5 failed logins.
Is Hikvision DVR DS-7204HGHI-F1 vulnerable to CVE-2020-7057?
No, Hikvision DVR DS-7204HGHI-F1 is not vulnerable to CVE-2020-7057.