Vulnerability Details CVE-2019-11064
A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text via cgibin/ExportSettings.cgi?Export=1 without any authentication.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2019-11064
-
cpe:2.3:h:androvideo:vd_1:-
-
cpe:2.3:h:geovision:gv-vd8700:-
-
cpe:2.3:h:geovision:gv-vr360:-
-
cpe:2.3:o:androvideo:vd_1_firmware:230
-
cpe:2.3:o:geovision:gv-vd8700_firmware:1.01
-
cpe:2.3:o:geovision:gv-vr360_firmware:1.03
-
cpe:2.3:o:geovision:gv-vr360_firmware:1.10