CVE Feed

    Dashboard / CVE / CVE-2020-11625

    CVE-2020-11625

    An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. Failed web UI login attempts elicit different responses depending on whether a user account exists. Because the responses indicate whether a submitted username is valid or not, they make it easier to identify legitimate usernames. If a login request is sent to ISAPI/Security/sessionLogin/capabilities using a username that exists, it will return the value of the salt given to that username, even if the password is incorrect. However, if a login request is sent using a username that is not present in the database, it will return an empty salt value. This allows attackers to enumerate legitimate usernames, facilitating brute-force attacks. NOTE: this is different from CVE-2020-7057.

    Published:Jul 23, 2020
    Last Modified:Nov 21, 2024
    EPS:Jul 23, 2020
    EPSS Score:0.00471
    CVSS Score:5.3

    Affected Products

    Vendor
    Avertx
    Product
    Hd438
    Vendor
    Avertx
    Product
    Hd438 Firmware
    Vendor
    Avertx
    Product
    Hd838
    Vendor
    Avertx
    Product
    Hd838 Firmware

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High