VulnerabilityModified
CVE-2020-10513
The file management interface of iCatch DVR firmware before 20200103 contains broken access control which allows the attacker to remotely manipulate arbitrary file.
MEDIUM 6.5EPSS 0.82%
Does this matter?
Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.
Description
The file management interface of iCatch DVR firmware before 20200103 contains broken access control which allows the attacker to remotely manipulate arbitrary file.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- icatchinc/dvr interface
- Source
- twcert@cert.org.tw
References
- https://www.chtsecurity.com/news/008fcbe8-198e-4c21-9417-5ba79a6b0e7dThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-3533-10afe-1.htmlThird Party Advisory
- https://www.chtsecurity.com/news/008fcbe8-198e-4c21-9417-5ba79a6b0e7dThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-3533-10afe-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.