First published: Sat Mar 02 2024(Updated: )
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
Credit: hsrc@hikvision.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hikvision Hikcentral Professional | >=2.0.0<2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25064 is rated as a medium severity vulnerability due to the impact it can have when exploited.
To fix CVE-2024-25064, ensure that you update Hikvision Hikcentral Professional to a version above 2.5.1.
CVE-2024-25064 is categorized as an insufficient server-side validation vulnerability.
Users of Hikvision Hikcentral Professional versions between 2.0.0 and 2.5.1 are affected by CVE-2024-25064.
An attacker with login privileges can access unauthorized resources by manipulating parameter values.