PT-2026-97112 · Openeye · Apex Network Video Recorder
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEye Apex Network Video Recorder versions 2.2.3.4 through 3.2.9.376
Description
The software trusts an
X-Forwarded-For header provided by a client to determine the request source address. This allows an unauthenticated remote attacker to spoof a loopback address and bypass security controls that restrict access to local connections on non-TLS web interfaces, leading to the disclosure of configuration information.Recommendations
Upgrade to version 3.5.4.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apex Network Video Recorder