CVE-2024-56902: Infoleak
Published Feb 3, 2025
·Updated
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.
Affected Software
1 affected component
GeoVision GV-ASManager<=6.1.0.0
Event History
Feb 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Apr 8, 2025
Exploit Published
12:00 AM
Known Exploited
09:47 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-56902?
CVE-2024-56902 is classified as a medium severity vulnerability due to the potential for unauthorized access to account information.
2
How do I fix CVE-2024-56902?
To fix CVE-2024-56902, upgrade Geovision GV-ASWeb to version 6.1.0.1 or later that addresses this vulnerability.
3
What type of attack does CVE-2024-56902 allow?
CVE-2024-56902 allows unauthorized attackers with low-level privileges to retrieve information about other user accounts via crafted HTTP requests.
4
Which versions of Geovision GV-ASWeb are affected by CVE-2024-56902?
CVE-2024-56902 affects all versions of Geovision GV-ASWeb up to and including 6.1.0.0.
5
Who is the vendor responsible for CVE-2024-56902?
The vendor responsible for CVE-2024-56902 is Geovision.