Vulnerabilities > CVE-2022-39029 - Incorrect Authorization vulnerability in Lcnet Smart Evision 2022.02.21

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privilege, who is not explicitly authorized to access the information, can access sensitive information.

Vulnerable Configurations

Part Description Count
Application
Lcnet
2

Common Weakness Enumeration (CWE)