CVE-2024-56902 Details
Description
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.
A vulnerability allowing information disclosure has been identified in the GeoVision GV-ASManager web application, specifically in versions through 6.1.0.0. This vulnerability exposes account information, including passwords in cleartext.
Users are advised to update to GeoVision GV-ASManager version 6.1.2.0 or later. Version 6.1.1.0 also addresses this vulnerability but is still susceptible to a Cross-Site Request Forgery attack.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 3, 2025CISA-ADP
Assessed Mar 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DRAGOWN/CVE-2024-56902 | [email protected] | ExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| GeoVision GV-ASManager | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 4, 2025 | CVE Modified | CISA-ADP |
| Mar 3, 2025 | CVE Modified | [email protected] |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Feb 4, 2025 | CVE Modified | CISA-ADP |
| Feb 3, 2025 | New CVE Received | [email protected] |
Volerion