RULE(RULE ID:338250)

Rule General Information
Release Date: 2024-07-16
Rule Name: Crocus System Service.do Arbitrary File Read Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Streamax Technology is a commercial vehicle Intelligent Internet of Things (AIOT) solution provider focused on AI and video technologies. There is an arbitrary file reading vulnerability in the Service.do interface of Crocus system of Streamax Technology. An unauthenticated remote attacker can read system files, such as system configuration files, through this vulnerability.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.