The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25394.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50953 | GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used. The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25394. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-1682/ |
|
Thu, 14 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geovision
Geovision gv-asmanager |
|
| CPEs | cpe:2.3:a:geovision:gv-asmanager:6.1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Geovision
Geovision gv-asmanager |
Mon, 16 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Dec 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used. The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25394. | |
| Title | GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2024-12-16T17:55:27.880Z
Reserved: 2024-12-11T21:53:45.864Z
Link: CVE-2024-12553
Updated: 2024-12-16T17:55:24.348Z
Status : Analyzed
Published: 2024-12-13T23:15:06.310
Modified: 2025-08-14T18:47:20.423
Link: CVE-2024-12553
No data.
OpenCVE Enrichment
No data.
EUVD