Known Vulnerabilities for products from Castel
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Castel".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Additional devices specifications by Castel can be found at device.report : Castel
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-11682 json | Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web... | 6.5 - MEDIUM | 2020-06-04 | 2020-06-10 |
| CVE-2020-11681 json | Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users c... | 8.1 - HIGH | 2020-06-04 | 2020-06-10 |
| CVE-2020-11680 json | Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to ... | 6.5 - MEDIUM | 2020-06-04 | 2021-07-21 |
| CVE-2020-11679 json | Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality. Ad... | 8.8 - HIGH | 2020-06-04 | 2021-07-21 |
Known software with vulnerabilities from Castel
| Type | Vendor | Product | Version |
|---|---|---|---|
| Hardware | Castel | Nextgen Dvr | - |
| Operating System | Castel | Nextgen Dvr Firmware | 1.0.0 |