First published: Fri Jan 17 2020(Updated: )
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (ability to see every option but not modify them).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amcrest Web Server | =2.520.ac00.18.r |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7222.
The severity rating of CVE-2020-7222 is medium (5.3).
The affected software of CVE-2020-7222 is Amcrest Web Server version 2.520.AC00.18.R.
By changing the result parameter in the JavaScript code on the login page, an attacker can bypass authentication and achieve limited privileges.
Currently, there is no known fix available for CVE-2020-7222. It is recommended to update the software to the latest version once a fix has been released.