8.8

CVE-2020-10513

iCatch DVR - Broken Access Control

The file management interface of iCatch DVR firmware before 20200103 contains broken access control which allows the attacker to remotely manipulate arbitrary file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IcatchincDvr Interface Version < 20200103
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.82% 0.525
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
twcert@cert.org.tw 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

https://www.chtsecurity.com/news/008fcbe8-198e-4c21-9417-5ba79a6b0e7d
Third Party Advisory
https://www.twcert.org.tw/tw/cp-132-3533-10afe-1.html
Third Party Advisory