ZDI-24-1682: GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used. The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2024-12553.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1682?
The severity of ZDI-24-1682 is considered high due to its potential for sensitive information disclosure.
How do I fix ZDI-24-1682?
To fix ZDI-24-1682, ensure that default guest credentials are changed and apply the latest security patches for GeoVision GV-ASManager.
What systems are affected by ZDI-24-1682?
ZDI-24-1682 affects installations of GeoVision GV-ASManager that allow remote access.
Can ZDI-24-1682 be exploited without authentication?
Although ZDI-24-1682 requires authentication, it can be exploited using default guest credentials.
What type of vulnerability is ZDI-24-1682?
ZDI-24-1682 is a remote information disclosure vulnerability.