Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. Failed web UI login attempts elicit different responses depending on whether a user account exists. Because the responses indicate whether a submitted username is valid or not, they make it easier to identify legitimate usernames. If a login request is sent to ISAPI/Security/sessionLogin/capabilities using a username that exists, it will return the value of the salt given to that username, even if the password is incorrect. However, if a login request is sent using a username that is not present in the database, it will return an empty salt value. This allows attackers to enumerate legitimate usernames, facilitating brute-force attacks. NOTE: this is different from CVE-2020-7057.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838和HD438 安全漏洞
Vulnerability Description
AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838和Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438都是美国AvertX公司的一款网络摄像机设备。 AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838和HD438中存在安全漏洞。远程攻击者可通过枚举IP cameras
CVSS Information
N/A
Vulnerability Type
N/A