vendor:
Network Video Server
by:
SecurityFocus
7.5
CVSS
HIGH
Access Validation Error
287
CWE
Product Name: Network Video Server
Affected Version From: Model 132
Affected Version To: Model 132
Patch Exists: NO
Related CWE: N/A
CPE: h:flexwatch:network_video_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
FlexWATCH Network Video Server Access Validation Error
It has been reported that FlexWATCH Network Video Server may be prone to an access validation error that may allow a remote attacker to gain administrative access to the system. The problem is reported to present itself when an attacker attempts to access the administrative interface using a specially crafted URL containing two slash '/' characters. Successful exploitation of this issue may allow a remote attacker to gain administrator level privileges to the server. This may lead to user accounts and system configuration modifications.
Mitigation:
Administrators should ensure that access to the administrative interface is restricted to trusted hosts.