Vulnerability Description
NVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the server twice. In the second package, the server will return the correct password information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nvs365 | Nvs-365-V01 Firmware | - |
| Nvs365 | Nvs-365-V01 | - |
Related Weaknesses (CWE)
References
- https://github.com/Sylon001/NVS-365-Camera/tree/master/NVS365%20Network%20Video%ExploitThird Party Advisory
- https://github.com/Sylon001/NVS365/tree/main/NVS-365-V01%E6%91%84%E5%83%8F%E5%A4Broken Link
- https://github.com/Sylon001/NVS-365-Camera/tree/master/NVS365%20Network%20Video%ExploitThird Party Advisory
- https://github.com/Sylon001/NVS365/tree/main/NVS-365-V01%E6%91%84%E5%83%8F%E5%A4Broken Link
FAQ
What is CVE-2022-47070?
CVE-2022-47070 is a vulnerability with a CVSS score of 7.5 (HIGH). NVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the server twice. In the second package, the server will return the correct password info...
How severe is CVE-2022-47070?
CVE-2022-47070 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-47070?
Check the references section above for vendor advisories and patch information. Affected products include: Nvs365 Nvs-365-V01 Firmware, Nvs365 Nvs-365-V01.