PT-2020-12770 · Castel · Castel Nextgen Dvr

Published

2020-06-04

·

Updated

2020-06-10

·

CVE-2020-11682

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Castel NextGen DVR version 1.0.0
Description The issue concerns a CSRF vulnerability in state-changing requests. A RequestVerificationToken is set by the web interface and included in requests sent by the web interface. However, this token is not verified by the application, allowing the token to be removed from all requests without preventing the request from succeeding.
Recommendations For Castel NextGen DVR version 1.0.0, as a temporary workaround, consider implementing a custom verification mechanism for the RequestVerificationToken to ensure its presence and validity in all state-changing requests until a patch is available.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11682

Affected Products

Castel Nextgen Dvr