VYPR
Unrated severityNVD Advisory· Published Oct 3, 2023· Updated Sep 19, 2024

ByDemes Group Airspace CCTV Web Service Improper Access Control

CVE-2023-0506

Description

The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privileged attacker to gain administrator access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Privilege escalation in ByDemes Group Airspace CCTV Web Service 2.616.BY00.11 allows a low-privileged attacker to gain admin access via the Camera Control Panel.

Vulnerability

The web service of the ByDemes Group Airspace CCTV Web Service, in version 2.616.BY00.11, contains an improper access control vulnerability (CWE-284). The flaw resides in the Camera Control Panel, where the authorization schema does not properly enforce privilege checks, allowing lower-privileged users to access administrator-level functions. [2]

Exploitation

An attacker needs only a low-privileged (standard user) account on the web service. No other special network position or user interaction is required. By manipulating HTTP requests to the Camera Control Panel endpoints (as described in general bypassing authorization schema testing [1]), the attacker can access and invoke administrative functions. The vulnerability does not require any race condition or additional authentication bypass; standard HTTP request manipulation is sufficient. [2]

Impact

Successful exploitation leads to complete privilege escalation, granting the attacker administrator-level access to the Camera Control Panel. This results in full compromise of the CCTV management interface, with potential for unauthorized access to video feeds, configuration changes, and further system control. The CVSS v3.1 base score of 8.8 reflects high impact on confidentiality, integrity, and availability. [2]

Mitigation

The ByDemes Group security team has released a fix; affected users should upgrade to the latest available version. However, the affected devices are at end of life and no longer supported, so upgrading to a newer model is strongly recommended. No workaround is documented. [2]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.