Vulnerabilities > CVE-2020-11679 - Missing Authorization vulnerability in Castel Nextgen DVR Firmware 1.0.0

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
castel
CWE-862

Summary

Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality. Adminstrator/Users/Edit/:UserId fails to check that the request was submitted by an Administrator. This allows a normal user to escalate their privileges by adding additional roles to their account.

Vulnerable Configurations

Part Description Count
OS
Castel
1
Hardware
Castel
1

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/157954/castelnextgendvr100-bypassdisclosexsrf.txt
idPACKETSTORM:157954
last seen2020-06-06
published2020-06-05
reporterAaron Bishop
sourcehttps://packetstormsecurity.com/files/157954/Castel-NextGen-DVR-1.0.0-Bypass-CSRF-Disclosure.html
titleCastel NextGen DVR 1.0.0 Bypass / CSRF / Disclosure