CVE-2024-36523

MEDIUM

Wvp GB28181 Pro 2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

An access control issue in Wvp GB28181 Pro 2.0 allows users to continue to access information in the application after deleting their own or administrator accounts. This is provided that the users do not log out of their deleted accounts.

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (1)
wvp-pro/gb28181 2.0
Published Jun 12, 2024
Tracked Since Feb 18, 2026