Impact
The vulnerability is an authentication bypass that allows an unauth or HTTPS requests to affected Digital Watchdog devices. Once the bypass succeeds, the device returns sensitive information, including administrator credentials stored in plaintext. This flaw results in the disclosure of device configuration details and access credentials, compromising the confidentiality of the device and any network it is connected to. This flaw is an instance of Missing Authentication (CWE-306).
Affected Systems
Digital Watchdog products affected include the VA1G4 Recorder, VG4 Recorder, VMAX A1 G4, VMAX A1 PLUS, and VMAX IP G4 NVR. No specific firmware or model versions are listed, so any running firmware on these models is considered vulnerable until patched.
Risk and Exploitability
The CVSS score of 7.1 indicates medium to high severity, while the EPSS score of less than 1% suggests that active exploitation is unlikely in the near term. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been documented. The attack is inferred to be executed remotely over the device’s HTTP(S) interface, requiring no credentials to trigger the authentication bypass and enabling the attacker to read sensitive information immediately after the bypass is achieved.
OpenCVE Enrichment