packetstormsecurity.com
http://packetstormsecurity.com/files/132437/Kguard-Digital-Video-Recorder-Bypass-Issues.html CVE-2015-4464
CRITICAL
kguardsecurity kg-sha104_firmware Improper Authentication
Record summary
CVE-2015-4464 has a selected CVSS score of 9.8 (critical).
Description
Kguard Digital Video Recorder 104, 108, v2 does not have any authorization or authentication between an ActiveX client and the application server.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 1, 2019 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
kg-sha104_firmwareBrowse kguardsecurity / kg-sha104_firmware | VulnCheck | Version data not supplied | |
References
520150624 CVE-2015-4464 Insufficient Authorization Checks Request Handling Remote Authentication Bypass for Kguard Digital Video Recordersmailing list
http://www.securityfocus.com/archive/1/535822/100/0/threaded 73032vdb entry
http://www.securityfocus.com/bid/73032 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-4464 academia.edu
https://www.academia.edu/11677554/Kguard_Digital_Video_Recorders_Multiple_Vulnerabilities