CVE-2024-25064: Medium severity hikvision hikcentral professional vulnerability
Published Mar 2, 2024
·Updated
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
Affected Software
1 affected component
Hikvision Hikcentral Professional>=2.0.0<2.5.1
Event History
Mar 2, 2024
CVE Published
via MITRE·02:56 AM
Data Sourced
via MITRE·02:56 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-25064?
CVE-2024-25064 is rated as a medium severity vulnerability due to the impact it can have when exploited.
2
How do I fix CVE-2024-25064?
To fix CVE-2024-25064, ensure that you update Hikvision Hikcentral Professional to a version above 2.5.1.
3
What type of vulnerability is CVE-2024-25064?
CVE-2024-25064 is categorized as an insufficient server-side validation vulnerability.
4
Who could be affected by CVE-2024-25064?
Users of Hikvision Hikcentral Professional versions between 2.0.0 and 2.5.1 are affected by CVE-2024-25064.
5
What can an attacker do with CVE-2024-25064?
An attacker with login privileges can access unauthorized resources by manipulating parameter values.