PT-2025-3344 · Geovision · Geovision Gv-Asweb
Published
2025-02-03
·
Updated
2025-04-08
·
CVE-2024-56902
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Geovision GV-ASWeb versions 6.1.0.0 and earlier
Description
The issue allows unauthorized attackers with low-level privileges to request information about other accounts via a crafted HTTP request.
Recommendations
For Geovision GV-ASWeb versions 6.1.0.0 and earlier, consider restricting access to sensitive account information until a patch is available.
As a temporary workaround, avoid using the vulnerable version of Geovision GV-ASWeb to minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Geovision Gv-Asweb