CVE-2020-7222: Medium severity Amcrest Web Server vulnerability
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (ability to see every option but not modify them).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-7222.
What is the severity rating of CVE-2020-7222?
The severity rating of CVE-2020-7222 is medium (5.3).
What is the affected software of CVE-2020-7222?
The affected software of CVE-2020-7222 is Amcrest Web Server version 2.520.AC00.18.R.
How can an attacker exploit CVE-2020-7222?
By changing the result parameter in the JavaScript code on the login page, an attacker can bypass authentication and achieve limited privileges.
Is there a fix available for CVE-2020-7222?
Currently, there is no known fix available for CVE-2020-7222. It is recommended to update the software to the latest version once a fix has been released.