CVE-2020-11681
Summary
| CVE | CVE-2020-11681 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-04 19:15:00 UTC |
| Updated | 2020-06-10 17:31:00 UTC |
| Description | Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credentials. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Castel | Nextgen Dvr | - | All | All | All |
| Hardware | Castel | Nextgen Dvr | - | All | All | All |
| Operating System | Castel | Nextgen Dvr Firmware | 1.0.0 | All | All | All |
| Operating System | Castel | Nextgen Dvr Firmware | 1.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Castel NextGen DVR 1.0.0 Bypass / CSRF / Disclosure ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory |
| Full Disclosure: Castel NextGen DVR multiple CVEs | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| Authorization Bypass: A Cautionary Tale CVE (2020-11679, 2020-11680, 2020-11681) | MISC | www.securitymetrics.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.