// For flags

CVE-2019-11064

A vulnerability of remote credential disclosure was discovered in Advan VD-1

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password in plain text via cgibin/ExportSettings.cgi?Export=1 without any authentication.

Se descubrió una vulnerabilidad de divulgación remota de credenciales en las versiones de firmware Advan VD-1 hasta 230. Un atacante puede exportar la configuración del sistema que no está encriptada para obtener la cuenta y la contraseña del administrador en texto plano a través de cgibin / ExportSettings.cgi? Export = 1 sin cualquier autenticación

*Credits: Keniver Wang (CHT Security)
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-04-09 CVE Reserved
  • 2019-08-29 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 First Exploit
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Androvideo
Search vendor "Androvideo"
Vd 1 Firmware
Search vendor "Androvideo" for product "Vd 1 Firmware"
<= 230
Search vendor "Androvideo" for product "Vd 1 Firmware" and version " <= 230"
-
Affected
in Androvideo
Search vendor "Androvideo"
Vd 1
Search vendor "Androvideo" for product "Vd 1"
--
Safe
Geovision
Search vendor "Geovision"
Gv-vr360 Firmware
Search vendor "Geovision" for product "Gv-vr360 Firmware"
<= 1.10
Search vendor "Geovision" for product "Gv-vr360 Firmware" and version " <= 1.10"
-
Affected
in Geovision
Search vendor "Geovision"
Gv-vr360
Search vendor "Geovision" for product "Gv-vr360"
--
Safe
Geovision
Search vendor "Geovision"
Gv-vd8700 Firmware
Search vendor "Geovision" for product "Gv-vd8700 Firmware"
<= 1.01
Search vendor "Geovision" for product "Gv-vd8700 Firmware" and version " <= 1.01"
-
Affected
in Geovision
Search vendor "Geovision"
Gv-vd8700
Search vendor "Geovision" for product "Gv-vd8700"
--
Safe