Vulnerability Description
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and brute force the salt offline, leading to forging a legitimate password recovery code for the admin user.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wwbn | Avideo | 15fed957fb |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2023-1900ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2023-1900ExploitThird Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1900
FAQ
What is CVE-2023-49599?
CVE-2023-49599 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalat...
How severe is CVE-2023-49599?
CVE-2023-49599 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-49599?
Check the references section above for vendor advisories and patch information. Affected products include: Wwbn Avideo.