CVE-2024-56902
moderateUnauthenticated Information Disclosure in GeoVision GV-ASManager (<= 6.1.0.0)
GeoVision's GV-ASManager web application, the management interface for its access control platform, contains an information disclosure flaw (CWE-200) that exposes account information, including passwords stored or transmitted in cleartext. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the flaw is reachable over the network without authentication, privileges, or user interaction. A remote, unauthenticated attacker who can reach the vulnerable web interface can harvest account credentials, including cleartext passwords, potentially gaining access to the access control management system and the accounts it manages. Affected organizations are those running GV-ASManager version v6.1.0.0 or earlier. No public proof-of-concept or confirmed in-the-wild exploitation is known and the flaw is not in CISA's KEV catalog, but the elevated EPSS score (23.4%, 98th percentile) suggests a meaningful probability of exploitation within the next 30 days.
What to do: Upgrade GV-ASManager to a release newer than v6.1.0.0 once GeoVision publishes a fixed version, and confirm the fix scope with the vendor. Until then, restrict access to the ASManager web interface to trusted networks (firewall rules or VPN) rather than exposing it directly to the internet. Because account passwords may be disclosed in cleartext, audit exposed accounts and rotate those credentials, especially any reused for other systems.
| GeoVision GV-ASManager | v6.1.0.0 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.