CVE-2024-25063

HIGH

Hikvision HikCentral Professional <= 2.5.1 - Improper Authorization

Title source: llm
STIX 2.1

Description

Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to.

Scores

CVSS v3 7.5
EPSS 0.0057
EPSS Percentile 42.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (1)
hikvision/hikcentral_professional < 2.5.1
Published Mar 02, 2024
Tracked Since Feb 18, 2026