Lucene search

K
nvd[email protected]NVD:CVE-2023-27055
HistoryMar 24, 2023 - 10:15 p.m.

CVE-2023-27055

2023-03-2422:15:07
CWE-22
web.nvd.nist.gov
4
cve-2023-27055
aver information inc
ptzapp2
sensitive files
crafted get request

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

52.5%

Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.

Affected configurations

Nvd
Node
averptzapp_2Range<2.0.1051.53
VendorProductVersionCPE
averptzapp_2*cpe:2.3:a:aver:ptzapp_2:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

52.5%

Related for NVD:CVE-2023-27055