SN No. HSRC-202403-01
Edit: Hikvision Security Response Center (HSRC)
Initial Release Date: 2024-03-01
Summary
(1) Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to.
(2) Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
CVE ID
CVE-2024-25063
CVE-2024-25064
Scoring
CVSS v3.1 is adopted in scoring these vulnerabilities (http://www.first.org/cvss/specification-document)
CVE-2024-25063
Base score:7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVE-2024-25064
Base score:4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)