CVE-2023-49599: Critical severity wwbn avideo vulnerability
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and bruteforce the salt offline, leading to forging a legitimate password recovery code for the admin user.
Other sources
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and brute force the salt offline, leading to forging a legitimate password recovery code for the admin user.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49599?
CVE-2023-49599 is classified as a critical vulnerability due to its potential for privilege escalation.
How do I fix CVE-2023-49599?
To remediate CVE-2023-49599, update to the latest version of WWBN AVideo that addresses the insufficient entropy in salt generation.
What software versions are affected by CVE-2023-49599?
CVE-2023-49599 affects WWBN AVideo versions up to and including 12.4 and the specific commit 15fed957fb.
Can an attacker exploit CVE-2023-49599 remotely?
Yes, an attacker can exploit CVE-2023-49599 by sending specially crafted HTTP requests to the affected system.
What are the consequences of exploiting CVE-2023-49599?
Exploitation of CVE-2023-49599 can lead to privilege escalation and unauthorized system access.