vendor:
Arteco DVR/NVR
by:
LiquidWorm
7.5
CVSS
HIGH
Session Hijacking
287
CWE
Product Name: Arteco DVR/NVR
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 10 Enterprise, Apache/2.4.39 (Win64) OpenSSL/1.0.2s, Apache/2.2.29 (Win32) mod_fastcgi/2.4.6 mod_ssl/2.2.29 OpenSSL/1.0.1m, Arteco-Server
2020
Arteco Web Client DVR/NVR – ‘SessionId’ Brute Force
The Session ID 'SessionId' is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication and disclose the live camera stream.
Mitigation:
Ensure that the Session ID is of sufficient length and complexity.