CVE-2023-27055
Description
Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A directory traversal vulnerability in Aver PTZApp2 allows remote attackers to read arbitrary files via a crafted GET request.
Vulnerability
A directory traversal vulnerability exists in Aver Information Inc.'s PTZApp2, a web application used to control AVer USB cameras, running on localhost. Versions prior to update 2.0.1051.53, including v20.01044.48, are affected. The vulnerability stems from insufficient filtering and validation of user-supplied input in GET requests, allowing path traversal sequences to access files outside the intended directory [1].
Exploitation
An attacker can exploit this vulnerability by sending a crafted GET request to the web application. No authentication is required. The attacker can use path traversal sequences (e.g., '../' or '..\\') to navigate the filesystem. A proof-of-concept script demonstrates reading the HOSTS file, but other sensitive files can be targeted [1].
Impact
Successful exploitation allows an attacker to read arbitrary files on the system, including sensitive configuration files, public and private keys of the web application server, and other confidential data. This leads to information disclosure, potentially compromising further security measures [1].
Mitigation
Aver has released an update (version 2.0.1051.53) that fixes this vulnerability. Users should upgrade to this version or later. There is no workaround provided for unpatched versions [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Aver Information Inc/PTZApp2description
- Range: =20.01044.48
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
News mentions
0No linked articles in our index yet.