CVE-2025-64770
BaseFortify
Publication date: 2025-11-20
Last updated on: 2025-11-21
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability allows unauthenticated access to Open Network Video Interface Forum (ONVIF) services on affected products. This means an attacker can access camera configuration information without needing to log in or authenticate, potentially gaining unauthorized control or insight into the device settings.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing attackers to gain unauthorized access to camera configuration information. This could lead to privacy breaches, unauthorized surveillance, or manipulation of camera settings, potentially compromising security and safety.