Description
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.
Problem types
CWE-341 Predictable from observable state
Product status
1.10
1.12
Timeline
| 2026-02-17: | Initial Vendor Contact |
Credits
Philippe Laulheret of Cisco Talos.
Kelly Patterson of Cisco Talos.
Martin Zeiser of Cisco Talos.
References
www.geovision.com.tw/cyber_security.php
talosintelligence.com/vulnerability_reports/