vendor:
Pelco VideoXpert
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Missing Encryption Of Sensitive Information
311
CWE
Product Name: Pelco VideoXpert
Affected Version From: 1.12.0105
Affected Version To: 2.0.41
Patch Exists: NO
Related CWE:
CPE: a:schneider_electric:pelco_videoxpert:1.14.7
Platforms Tested: Microsoft Windows 7 Professional SP1 (EN), Jetty(9.2.6.v20141205), MongoDB/3.2.10
2017
Schneider Electric Pelco VideoXpert Missing Encryption Of Sensitive Information
The software transmits sensitive data using double Base64 encoding for the Cookie 'auth_token' in a communication channel that can be sniffed by unauthorized actors or arbitrarily be read from the vxcore log file directly using directory traversal attack resulting in authentication bypass / session hijacking.
Mitigation:
Encrypt the sensitive data transmitted in the communication channel to prevent unauthorized access and session hijacking. Implement secure coding practices.