Sceawere
Vulnerability Detail
CVE-2026-103098UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Sensitive Key Exposure via HTTP
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 22h ago
- Vendor
- GeoVision Inc.
- Product
- GV-Eye
- Attack Type
- CWE-319 Cleartext transmission of sensitive information
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-02T01:16:43.193Z",
"pubdate": "2026-10-02T01:16:43.193Z",
"executiveSummary": "The vulnerability involves the transmission of sensitive cryptographic or authentication keys via URL parameters over an insecure HTTP connection. Because HTTP lacks encryption, these keys are transmitted in plaintext across the network, exposing them to interception by unauthorized parties.\nThe vulnerability type is classified as Information Exposure through Sensitive Information in Uniform Resource Locator (URL).\nThe impact is significant, as successful exploitation results in the unauthorized disclosure of sensitive credentials, which could lead to full system compromise, unauthorized access to secure resources, or identity impersonation.\nThe threat model assumes an attacker capable of performing passive or active network monitoring, such as Man-in-the-Middle (MitM) attacks, within the same network segment or via compromised infrastructure between the client and the server.\nThis vulnerability affects any web-based application or system that relies on plaintext HTTP to handle sensitive parameters. The primary risk implication is the trivial acquisition of secret keys, bypassing perimeter security and authentication controls without requiring prior privileges or complex exploit payloads.",
"technicalDetails": "The root cause of this vulnerability is the failure to enforce transport-layer security (TLS/SSL) for requests containing sensitive data. By utilizing the HTTP protocol, the system transmits the complete request, including the URL and its associated query string, in a format that is not cryptographically protected.\nIn standard web architecture, URLs are often logged by intermediate devices such as proxies, load balancers, and web servers. Furthermore, when sensitive data is included in the URL, it is exposed to the Referer header, browser history, and network-level interception. Because HTTP provides no confidentiality or integrity protections, any entity positioned between the sender and the receiver can inspect the packet headers and body.\nThe attack flow proceeds as follows: 1. The application generates a request containing a sensitive key as a URL parameter. 2. The client transmits this request over HTTP. 3. An attacker positioned on the network uses packet sniffing tools (e.g., Wireshark or tcpdump) to capture the cleartext HTTP traffic. 4. The attacker parses the HTTP GET request and extracts the key from the URI string. 5. Once the key is obtained, the attacker performs unauthorized actions or accesses restricted resources by presenting the intercepted key to the server.\nThe vulnerable component is the communication interface that allows or mandates the use of plaintext HTTP for operations involving sensitive data transmission. This exposure occurs regardless of whether the key is static or session-based. The reliance on URL parameters for sensitive keys further exacerbates the issue, as URL data is inherently more visible than data contained within the HTTP POST request body.\nPost-exploitation impact includes unauthorized data exfiltration, persistent unauthorized access, or the ability to forge requests that appear legitimate to the backend system. Because the key is captured in transit, no special authentication or privilege levels are required by the attacker; the vulnerability is accessible to any entity capable of observing the network path. The lack of encryption ensures that the interception is silent and does not require complex interactions with the target system, making it an ideal target for reconnaissance and credential harvesting campaigns."
}