Vulnerability Description
Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credentials.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Castel | Nextgen Dvr Firmware | 1.0.0 |
| Castel | Nextgen Dvr | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/157954/Castel-NextGen-DVR-1.0.0-Bypass-CSRFThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Jun/8Mailing ListThird Party Advisory
- https://www.securitymetrics.com/blog/attackers-known-unknown-authorization-bypasThird Party Advisory
- http://packetstormsecurity.com/files/157954/Castel-NextGen-DVR-1.0.0-Bypass-CSRFThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Jun/8Mailing ListThird Party Advisory
- https://www.securitymetrics.com/blog/attackers-known-unknown-authorization-bypasThird Party Advisory
FAQ
What is CVE-2020-11681?
CVE-2020-11681 is a vulnerability with a CVSS score of 8.1 (HIGH). Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credent...
How severe is CVE-2020-11681?
CVE-2020-11681 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11681?
Check the references section above for vendor advisories and patch information. Affected products include: Castel Nextgen Dvr Firmware, Castel Nextgen Dvr.