CVE-2023-3638: GeoVision GV-ADR2701 Improper Authentication
Published Jul 19, 2023
·Updated
In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.
Affected Software
5 affected components
GeoVision GV-ADR2701: Version V1.00_2017_12_15
GeoVision Gv-adr2701 Firmware=1.00_2017_12_15
GeoVision GV-ADR2701
All of the following
GeoVision Gv-adr2701 Firmware=1.00_2017_12_15
GeoVision GV-ADR2701
Event History
Jul 19, 2023
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
RemedyDescriptionSeverityWeakness
Data Sourced
03:15 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-3638?
The severity of CVE-2023-3638 is considered high due to its potential for unauthorized access to the web application.
2
How do I fix CVE-2023-3638?
To fix CVE-2023-3638, update the GeoVision GV-ADR2701 firmware to a version newer than 1.00_2017_12_15.
3
What systems are affected by CVE-2023-3638?
CVE-2023-3638 affects GeoVision GV-ADR2701 cameras running firmware version 1.00_2017_12_15.
4
What kind of attack does CVE-2023-3638 facilitate?
CVE-2023-3638 facilitates an attack where an attacker can edit the login response to gain access to the web application.
5
Who is the vendor for CVE-2023-3638?
The vendor for CVE-2023-3638 is GeoVision, specifically for the GV-ADR2701 product.