Improper Initialization vulnerability in local server authentication logic
CVE-2022-2472

7.6HIGH

Key Information:

Vendor

Ezviz

Vendor
CVE Published:
15 September 2022

What is CVE-2022-2472?

Improper Initialization vulnerability in the local server component of EZVIZ CS-C6N-A0-1C2WFR allows a local attacker to read the contents of the memory space containing the encrypted admin password. This issue affects: EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428.

Affected Version(s)

CS-C6N-A0-1C2WFR < 5.3.0 build 220428

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bitdefender Labs
.