Schneider Electric Pelco VideoXpert Missing Encryption

Discussion in 'News Aggregator' started by Packet Storm, 11 Jul 2017.

  1. Packet Storm

    Packet Storm Guest

    Schneider Electric Pelco VideoXpert transmits sensitive data using double Base64 encoding for the Cookie 'auth_token' in a communication channel that can be sniffed by unauthorized actors or arbitrarily be read from the vxcore log file directly using directory traversal attack resulting in authentication bypass / session hijacking.

    Continue reading...
     

Share This Page

Loading...