Vulnerabilities > CVE-2020-24216

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE

Summary

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is still available via its default name such as /0. Unauthenticated attackers can view video streams that are meant to be private.

Vulnerable Configurations

Part Description Count
OS
Szuray
2
OS
Jtechdigital
1
OS
Provideoinstruments
4
Hardware
Szuray
93
Hardware
Jtechdigital
1
Hardware
Provideoinstruments
4