CVE-2020-7222
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (ability to see every option but not modify them).
Se detectó un problema en Amcrest Web Server versión 2.520.AC00.18.R 2017-06-29 WEB versión 3.2.1.453504. La página de inicio de sesión responde con JavaScript cuando uno intenta autenticarse. Un atacante que cambia el parámetro result (a verdadero) en este código JavaScript puede omitir la autenticación y alcanzar privilegios limitados (capacidad de visualizar todas las opciones pero sin modificarlas).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-17 CVE Reserved
- 2020-01-17 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://sku11army.blogspot.com/2020/01/amcrest-2520ac0018r-login-bypass.html | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Amcrest Search vendor "Amcrest" | Web Server Search vendor "Amcrest" for product "Web Server" | 2.520.ac00.18.r Search vendor "Amcrest" for product "Web Server" and version "2.520.ac00.18.r" | - |
Affected
|