Impact
A flaw in the authentication mechanism for video stream requests allows an attacker to retrieve live feeds without credentials, effectivelyCWE-287). The result is that anyone reachable on the network can view real‑time video, potentially violating privacy, compromising recorded evidence, or enabling ongoing surveillance intrusion. This compromises the confidentiality and integrity of the security system.
Affected Systems
Genetec Security Center versions prior to build 5.14.178.18 (including 5.14.0.0 to 5.14.178.17) are affected. Any installation of Genetec Security Center that has not been upgraded to 5.14.178.18 or newer is at risk.
Risk and Exploitability
The CVSS score of 7.5 vulnerability, while the EPSS score of less than 1% suggests that, at present, the likelihood of widespread attacks have been detected, as it is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack surface relies on network access to the live‑video API endpoint; the description does not explicitly state this vector. No prior authentication or elevated privileges are required. Once accessed, an attacker can continuously monitor live feeds, posing a significant privacy threat and potential operational disruption.
OpenCVE Enrichment