RULE(RULE ID:338174)

Rule General Information
Release Date: 2024-06-25
Rule Name: EasyCVR Smart Edge Gateway userlist Information Leakage Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: EasyCVR Smart Edge Gateway is a device based on edge computing and artificial intelligence technologies that aims to provide efficient video surveillance and intelligent analytics solutions. EasyCVR Smart Edge Gateway has an information leakage vulnerability. Attackers can obtain system user account and password information directly through the userlist interface, and log in the background for illegal operations. This rule is used to detect suspicious accesses to the userlist interface, there may be false positives, such as confirmation as a normal internal request, the rule can be ignored or turned off.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.