Description
The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration wizard immediately without a login prompt or credentials check.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
All versions
Credits
Souvik Kandar of Microsec (microsec.io) reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-308-02