ID

VAR-201502-0072


CVE

CVE-2015-1469


TITLE

SerVision HVG Video Gateway web interface contains multiple vulnerabilities

Trust: 0.8

sources: CERT/CC: VU#522460

DESCRIPTION

time.htm in the web interface on SerVision HVG Video Gateway devices with firmware through 2.2.26a100 allows remote authenticated users to gain privileges by leveraging a cookie received in an HTTP response, a different vulnerability than CVE-2015-0929 and CVE-2015-0930. This vulnerability CVE-2015-0929 and CVE-2015-0930 Is a different vulnerability.By a third party HTTP Response cookie By using reception, you may be able to obtain the authority. SerVision HVG Video Gateway is an intelligent video gateway product from SerVision, Israel

Trust: 2.97

sources: NVD: CVE-2015-1469 // CERT/CC: VU#522460 // JVNDB: JVNDB-2015-001445 // CNVD: CNVD-2015-01014 // VULHUB: VHN-79430

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-01014

AFFECTED PRODUCTS

vendor:servisionmodel:hvg video gatewayscope:lteversion:2.2.26a100

Trust: 1.8

vendor:servisionmodel: - scope: - version: -

Trust: 0.8

vendor:servisionmodel:hvg 400scope: - version: -

Trust: 0.8

vendor:servisionmodel:hvg video gateway 2.2.26a100scope: - version: -

Trust: 0.6

vendor:servisionmodel:hvg video gatewayscope:eqversion:2.2.26a100

Trust: 0.6

sources: CERT/CC: VU#522460 // CNVD: CNVD-2015-01014 // JVNDB: JVNDB-2015-001445 // CNNVD: CNNVD-201502-069 // NVD: CVE-2015-1469

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-1469
value: HIGH

Trust: 1.0

NVD: CVE-2015-1469
value: HIGH

Trust: 0.8

CNVD: CNVD-2015-01014
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201502-069
value: CRITICAL

Trust: 0.6

VULHUB: VHN-79430
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-1469
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-01014
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-79430
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-01014 // VULHUB: VHN-79430 // JVNDB: JVNDB-2015-001445 // CNNVD: CNNVD-201502-069 // NVD: CVE-2015-1469

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-79430 // JVNDB: JVNDB-2015-001445 // NVD: CVE-2015-1469

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201502-069

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201502-069

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-001445

PATCH

title:Downloads - Get the latest software from SerVisionurl:http://www.servision.net/downloads/

Trust: 0.8

title:SerVision HVG Video Gateway devices with firmware privilege escalation vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/55241

Trust: 0.6

sources: CNVD: CNVD-2015-01014 // JVNDB: JVNDB-2015-001445

EXTERNAL IDS

db:CERT/CCid:VU#522460

Trust: 3.1

db:NVDid:CVE-2015-1469

Trust: 3.1

db:JVNDBid:JVNDB-2015-001445

Trust: 0.8

db:CNNVDid:CNNVD-201502-069

Trust: 0.7

db:CNVDid:CNVD-2015-01014

Trust: 0.6

db:VULHUBid:VHN-79430

Trust: 0.1

sources: CERT/CC: VU#522460 // CNVD: CNVD-2015-01014 // VULHUB: VHN-79430 // JVNDB: JVNDB-2015-001445 // CNNVD: CNNVD-201502-069 // NVD: CVE-2015-1469

REFERENCES

url:http://www.kb.cert.org/vuls/id/522460

Trust: 2.3

url:http://cwe.mitre.org/data/definitions/288.html

Trust: 0.8

url:http://cwe.mitre.org/data/definitions/284.html

Trust: 0.8

url:http://cwe.mitre.org/data/definitions/259.html

Trust: 0.8

url:http://www.servision.net/downloads/

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-1469

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-1469

Trust: 0.8

sources: CERT/CC: VU#522460 // CNVD: CNVD-2015-01014 // VULHUB: VHN-79430 // JVNDB: JVNDB-2015-001445 // CNNVD: CNNVD-201502-069 // NVD: CVE-2015-1469

SOURCES

db:CERT/CCid:VU#522460
db:CNVDid:CNVD-2015-01014
db:VULHUBid:VHN-79430
db:JVNDBid:JVNDB-2015-001445
db:CNNVDid:CNNVD-201502-069
db:NVDid:CVE-2015-1469

LAST UPDATE DATE

2025-04-12T23:04:51.591000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#522460date:2015-02-02T00:00:00
db:CNVDid:CNVD-2015-01014date:2015-02-11T00:00:00
db:VULHUBid:VHN-79430date:2015-02-04T00:00:00
db:JVNDBid:JVNDB-2015-001445date:2015-02-13T00:00:00
db:CNNVDid:CNNVD-201502-069date:2015-02-04T00:00:00
db:NVDid:CVE-2015-1469date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CERT/CCid:VU#522460date:2015-02-02T00:00:00
db:CNVDid:CNVD-2015-01014date:2015-02-11T00:00:00
db:VULHUBid:VHN-79430date:2015-02-03T00:00:00
db:JVNDBid:JVNDB-2015-001445date:2015-02-13T00:00:00
db:CNNVDid:CNNVD-201502-069date:2015-02-04T00:00:00
db:NVDid:CVE-2015-1469date:2015-02-03T22:59:05.067