vendor:
SunVeillance Monitoring System
by:
Luca.Chiou
7.5
CVSS
HIGH
Incorrect Access Control
287
CWE
Product Name: SunVeillance Monitoring System
Affected Version From: all versions prior to v1.1.9e
Affected Version To: v1.1.9e
Patch Exists: YES
Related CWE: N/A
CPE: a:auo:sunveillance_monitoring_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Proprietary devices
2019
AUO SunVeillance Monitoring System 1.1.9e – Incorrect Access Control
An issue was discovered in AUO SunVeillance Monitoring System. There is an incorrect access control vulnerability that can allow the attacker to bypass the authentication mechanism, and upload files to the server without any authentication.
Mitigation:
Ensure that access control mechanisms are properly implemented and enforced.