8.6
CVE-2026-42365
- EPSS 0.33%
- Veröffentlicht 04.05.2026 00:42:08
- Zuletzt bearbeitet 15.06.2026 21:16:53
- Quelle 0df08a0e-a200-4957-9bb0-084f56
- CVE-Watchlists
- Unerledigt
GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Geovision ≫ Gv-lpc2011 Firmware Version1.10
Geovision ≫ Gv-lpc2211 Firmware Version1.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.244 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| 0df08a0e-a200-4957-9bb0-084f562506f9 | 8.6 | 3.9 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
|
CWE-341 Predictable from Observable State
A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.
https://www.geovision.com.tw/cyber_security.php
https://talosintelligence.com/vulnerability_reports/
https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2332