357
VMScore

CVE-2020-11680

Published: 04/06/2020 Updated: 21/07/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 357
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to check that a request was submitted by an administrator. Consequently, a normal user can perform actions including, but not limited to, creating/modifying the file store, creating/modifying alerts, creating/modifying users, etc.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

castel nextgen_dvr_firmware 1.0.0

Exploits

Castel NextGen DVR version 100 suffers from authorization bypass, credential disclosure, and cross site request forgery vulnerabilities ...