Schneider Electric Pelco VideoXpert...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary VideoXpert is a video management solution designed for scalability, fitting the needs surveillance operations of any size. VideoXpert Ultimate can also aggregate other VideoXpert systems, tying multiple video management systems into a single interface. ### Description The software transmits sensitive data using double Base64 encoding for the Cookie 'auth_token' in a communication channel that can be sniffed by unauthorized actors or arbitrarely be read from the vxcore log file directly using directory traversal attack resulting in authentication bypass / session hijacking. ### Vendor Schneider Electric SE - https://www.pelco.com ### Affected Version * 2.0.41 * 1.14.7 * 1.12.105 ### Tested On Microsoft Windows 7 Professional SP1 (EN) ### PoC After a user logs in, the web server creates a Cookie: auth_token which has the following value: ```...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息