June 26, 2023, 11:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.

cve delete distributor file files filesystem history input input validation malicious missing server services validation vhs video vulnerability vulnerable

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Risk and compliance specialist

@ ZainCash | Baghdad, Baghdad Governorate, Iraq

Information Security Compliance Analyst

@ Evelyn Partners | Liverpool, United Kingdom

Director of Security Engineering

@ Kasada | Melbourne