4.3
CVE-2024-25064
- EPSS 0.24%
- Veröffentlicht 02.03.2024 03:15:06
- Zuletzt bearbeitet 21.11.2024 09:00:10
- Quelle hsrc@hikvision.com
- CVE-Watchlists
- Unerledigt
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hikvision ≫ Hikcentral Professional Version >= 2.0.0 < 2.5.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.466 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| hsrc@hikvision.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|