VYPR
Unrated severityNVD Advisory· Published Mar 24, 2023· Updated Feb 21, 2025

CVE-2023-27055

CVE-2023-27055

Description

Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A directory traversal vulnerability in Aver PTZApp2 allows remote attackers to read arbitrary files via a crafted GET request.

Vulnerability

A directory traversal vulnerability exists in Aver Information Inc.'s PTZApp2, a web application used to control AVer USB cameras, running on localhost. Versions prior to update 2.0.1051.53, including v20.01044.48, are affected. The vulnerability stems from insufficient filtering and validation of user-supplied input in GET requests, allowing path traversal sequences to access files outside the intended directory [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted GET request to the web application. No authentication is required. The attacker can use path traversal sequences (e.g., '../' or '..\\') to navigate the filesystem. A proof-of-concept script demonstrates reading the HOSTS file, but other sensitive files can be targeted [1].

Impact

Successful exploitation allows an attacker to read arbitrary files on the system, including sensitive configuration files, public and private keys of the web application server, and other confidential data. This leads to information disclosure, potentially compromising further security measures [1].

Mitigation

Aver has released an update (version 2.0.1051.53) that fixes this vulnerability. Users should upgrade to this version or later. There is no workaround provided for unpatched versions [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

News mentions

0

No linked articles in our index yet.