Authentication Bypass Vulnerability in Amcrest Web Server
CVE-2020-7222

5.3MEDIUM

Key Information:

Vendor

Amcrest

Vendor
CVE Published:
18 January 2020

What is CVE-2020-7222?

An authentication bypass flaw exists in Amcrest Web Server version 2.520.AC00.18.R, where the login page returns JavaScript upon authentication attempts. By altering the result parameter within this code, an attacker can bypass authentication processes, gaining limited privileges. This allows unauthorized users to view options available in the interface without the ability to make modifications.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.