A vulnerability has been identified in SiNVR 3 Central...
Low severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 18, 2024
Description
Published by the National Vulnerability Database
Dec 12, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 18, 2024
A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). Both the SiNVR 3 Video Server and the Central Control Server (CCS) store user and device passwords by applying weak cryptography. A local attacker could exploit this vulnerability to extract the passwords from the user database and/or the device configuration files to conduct further attacks.
References