vendor:
Intelligent Digital Security System
by:
Gjoko 'LiquidWorm' Krstic
8.8
CVSS
HIGH
Unauthorized Live Stream Disclosure
284
CWE
Product Name: Intelligent Digital Security System
Affected Version From: 5brid DVR (HD6-532/516, DX6-516/508/504, MX6-516/508/504, EH6-504) 7brid DVR (HD3-16V2, DX3-16V2/08V2/04V2, MX3-08V2/04V2) Firmware: <=8.0 (000143)
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: a:rifatron:intelligent_digital_security_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Embedded Linux, Boa/0.94.14rc21
2019
Rifatron Intelligent Digital Security System (animate.cgi) Stream Disclosure
The DVR suffers from an unauthenticated and unauthorized live stream disclosure when animate.cgi script is called through Mobile Web Viewer module.
Mitigation:
Ensure that authentication is required for access to the animate.cgi script.