ZeroHour

CVE-2020-11681

CVSS 3.1
8.1 high
EPSS
1%p65
Published
()
Modified
Description

Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credentials.

Vendors
castel
Products
nextgen dvr firmware
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.