vendor:
Digital Video Protection (DVP)
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Authenticated Root Remote Code Execution
CWE
Product Name: Digital Video Protection (DVP)
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: CentOS
2018
VideoFlow Digital Video Protection DVP 10 Authenticated Root Remote Code Execution
The affected device suffers from authenticated remote code execution vulnerability. Including a CSRF, a remote attacker can exploit this issue and execute arbitrary system commands granting her system access with root privileges.
Mitigation:
Unknown