Cleartext Storage of Sensitive Information Exposes Camera Login Credentials to Attacks
CVE-2024-45175
8.8HIGH
What is CVE-2024-45175?
A vulnerability has been found in the C-MOR Video Surveillance product from Zainternet, where sensitive information, including camera login credentials, is stored in cleartext. This flaw allows attackers with filesystem access to exploit path traversal techniques to retrieve sensitive data related to the configured cameras and FTP server. As such, the security of user data is critically compromised, necessitating urgent attention to secure storage practices.
