Insufficient Entropy Vulnerability in WWBN AVideo by WWBN
CVE-2023-49599
What is CVE-2023-49599?
A vulnerability identified in the AVideo platform arises from insufficient entropy in its salt generation process. Attackers can exploit this weakness through specifically crafted HTTP requests, providing them with the capability to gather sensitive system information. By leveraging brute force techniques, an attacker can compromise the salt value offline, ultimately enabling them to create a legitimate password recovery code for the admin user. This creates significant security risks for environments using affected versions of the AVideo platform.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AVideo dev master commit 15fed957fb
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
