RULE(RULE ID:338038)

Rule General Information
Release Date: 2024-05-28
Rule Name: G-sky CMSV6 downloadLogger Arbitrary File Read Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: G-sky CMSV6 vehicle video monitoring platform is a monitoring platform developed by G-sky Software Technology Co., LTD. Tongtianxing CMSV6 products cover vehicle video recorder and soldier video recorder. Network surveillance cameras, driving recorders and other products of the video integrated platform. The downloadLogger interface of the CMSV6 vehicle video monitoring platform has an arbitrary file reading vulnerability. Attackers can read sensitive files on the server by constructing specific requests. This rule may have false positives. Please make a judgment combined with the specific hit situation to see whether the file specified by the fileName parameter is a server sensitive file.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.