GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exploit this vulnerability, default guest credentials may be used. The specific flaw exists within the GV-ASWeb service. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-25394.
Use CWE-862, Geovision vendor hub and Gv-Asmanager product page to widen CVE-2024-12553 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-46070 for nearby disclosures in the same product family.