vendor:
GV-ADR2701
by:
Chan Nyein Wai
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: GV-ADR2701
Affected Version From: V1.00_2017_12_15
Affected Version To: V1.00_2017_12_15
Patch Exists: NO
Related CWE:
CPE: h:geovision:gv-adr2701
Platforms Tested: Windows 10
2020
GeoVision Camera GV-ADR2701 – Authentication Bypass
An authentication bypass vulnerability exists in GeoVision Camera GV-ADR2701. By intercepting the login request with Burp and editing the response, an attacker can successfully log in to the web application.
Mitigation:
Ensure that authentication is properly implemented and enforced.