PT-2020-12770 · Castel · Castel Nextgen Dvr
Published
2020-06-04
·
Updated
2020-06-10
·
CVE-2020-11682
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Castel NextGen DVR version 1.0.0
Description
The issue concerns a CSRF vulnerability in state-changing requests. A
RequestVerificationToken is set by the web interface and included in requests sent by the web interface. However, this token is not verified by the application, allowing the token to be removed from all requests without preventing the request from succeeding.Recommendations
For Castel NextGen DVR version 1.0.0, as a temporary workaround, consider implementing a custom verification mechanism for the
RequestVerificationToken to ensure its presence and validity in all state-changing requests until a patch is available.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Castel Nextgen Dvr