vendor:
GV-ASManager
by:
Giorgi Dograshvili [DRAGOWN]
6.1
CVSS
HIGH
Broken Access Control
285
CWE
Product Name: GV-ASManager
Affected Version From: 6.1.0.0
Affected Version To: 6.1.0.0
Patch Exists: NO
Related CWE: CVE-2024-56898
CPE: a:geovision:gv-asmanager:6.1.0.0
Platforms Tested: Windows 10, Kali Linux
2025
Broken Access Control in GeoVision GV-ASManager
The vulnerability exists in GeoVision GV-ASManager web application version 6.1.0.0 or below. An attacker with network access and a low privilege account can perform unauthorized actions like enabling/disabling accounts, creating new accounts, modifying privileges, and accessing resources. After privilege escalation, the attacker can access monitoring cameras, employee information, change configurations, disrupt services, clone access control data, and retrieve cleartext passwords for further attacks.
Mitigation:
Upgrade GeoVision GV-ASManager to a version higher than 6.1.0.0. Restrict network access to the application. Change default Guest account credentials.