An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive information, for example login credentials of cameras, is stored in cleartext. Thus, an attacker with filesystem access, for example exploiting a path traversal attack, has access to the login data of all configured cameras, or the configured FTP server.
References
Link | Resource |
---|---|
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-028.txt | Exploit Vendor Advisory |
https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030 | Vendor Advisory |
http://seclists.org/fulldisclosure/2024/Sep/21 | Exploit Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
04 Sep 2025, 16:35
Type | Values Removed | Values Added |
---|---|---|
First Time |
C-mor
C-mor c-mor Video Surveillance |
|
References | () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-028.txt - Exploit, Vendor Advisory | |
References | () https://www.syss.de/pentest-blog/mehrere-sicherheitsschwachstellen-in-videoueberwachungssoftware-c-mor-syss-2024-020-bis-030 - Vendor Advisory | |
References | () http://seclists.org/fulldisclosure/2024/Sep/21 - Exploit, Mailing List, Third Party Advisory | |
CPE | cpe:2.3:a:c-mor:c-mor_video_surveillance:5.2401:*:*:*:*:*:*:* cpe:2.3:a:c-mor:c-mor_video_surveillance:6.00:patch_level_01:*:*:*:*:*:* |
21 Nov 2024, 09:37
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
05 Sep 2024, 18:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-22 CWE-312 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
05 Sep 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-05 16:15
Updated : 2025-09-04 16:35
NVD link : CVE-2024-45175
Mitre link : CVE-2024-45175
CVE.ORG link : CVE-2024-45175
JSON object : View
Products Affected
c-mor
- c-mor_video_surveillance