CVE-2024-25064
MEDIUMDescription
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
Is your site exposed to CVE-2024-25064?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| hikvision | hikcentral_professional |
References
Frequently Asked Questions
What is CVE-2024-25064? +
How severe is CVE-2024-25064? +
What products are affected by CVE-2024-25064? +
How do I check if I'm vulnerable to CVE-2024-25064? +
Related Vulnerabilities
There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data …
There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary …
Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commands.
Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain …
There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the …
There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the …