CVE-2024-56898

Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.
Configurations

No configuration.

History

22 Mar 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-284

04 Mar 2025, 22:15

Type Values Removed Values Added
CWE CWE-862
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : unknown

03 Mar 2025, 22:15

Type Values Removed Values Added
Summary (en) Incorrect access control in Geovision GV-ASWeb version 6.1.0.0 or less allows unauthorized attackers with low-level privileges to manage and create new user accounts via supplying a crafted HTTP request. (en) Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.

04 Feb 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
Summary
  • (es) El control de acceso incorrecto en Geovision GV-ASWeb versión 6.1.0.0 o anterior permite que atacantes no autorizados con privilegios de bajo nivel administren y creen nuevas cuentas de usuario mediante el suministro de una solicitud HTTP manipulada.
CWE CWE-862

03 Feb 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-03 21:15

Updated : 2025-03-22 14:15


NVD link : CVE-2024-56898

Mitre link : CVE-2024-56898

CVE.ORG link : CVE-2024-56898


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control