7.5
CVE-2024-25063
- EPSS 0.28%
- Veröffentlicht 02.03.2024 03:15:06
- Zuletzt bearbeitet 27.03.2025 16:15:22
- Quelle hsrc@hikvision.com
- CVE-Watchlists
- Unerledigt
Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hikvision ≫ Hikcentral Professional Version <= 2.5.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.507 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| hsrc@hikvision.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.