In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44282 In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.
Fixes

Solution

GeoVision recommends that users of these devices upgrade to newer models with the latest firmware update which they have verified are not vulnerable to this issue such as TDR2704, TDR2702, or TDR2700. Alternatively, users could restrict connection of these cameras to closed local area networks isolated from internet connection.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:31:09.285Z

Reserved: 2023-07-12T13:56:15.455Z

Link: CVE-2023-3638

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-07-19T15:15:11.257

Modified: 2024-11-21T08:17:43.683

Link: CVE-2023-3638

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.