Vulnerabilities > CVE-2020-11680 - Missing Authorization vulnerability in Castel Nextgen DVR Firmware 1.0.0

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
castel
CWE-862

Summary

Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to check that a request was submitted by an administrator. Consequently, a normal user can perform actions including, but not limited to, creating/modifying the file store, creating/modifying alerts, creating/modifying users, etc.

Vulnerable Configurations

Part Description Count
OS
Castel
1
Hardware
Castel
1

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/157954/castelnextgendvr100-bypassdisclosexsrf.txt
idPACKETSTORM:157954
last seen2020-06-06
published2020-06-05
reporterAaron Bishop
sourcehttps://packetstormsecurity.com/files/157954/Castel-NextGen-DVR-1.0.0-Bypass-CSRF-Disclosure.html
titleCastel NextGen DVR 1.0.0 Bypass / CSRF / Disclosure