Executive brief
VideoFlow Digital Video Protection (DVP) is a professional broadcast appliance used to ensure reliable live video delivery over IP networks. A security flaw allows an authenticated user to bypass folder restrictions and access sensitive system files, such as configuration data or password files. This could lead to the exposure of administrative credentials or other confidential system information, potentially compromising the entire broadcast infrastructure.
Technical details
An authenticated directory traversal vulnerability exists in several Perl scripts within the VideoFlow DVP web interface, including downloadsys.pl, download_xml.pl, download.pl, downloadmib.pl, and downloadFile.pl. The root cause is insufficient sanitization of the 'ID' parameter, which is used to construct file paths for download. An attacker with low-privileged credentials can use '../' sequences to escape the intended directory and read arbitrary system files, such as /etc/passwd. The vulnerability was verified on versions 2.10 and 1.40.0.15 running on CentOS. No official patch is mentioned in the advisory, though the vulnerability was disclosed in 2018.
Affected products
- VideoFlow Ltd. Digital Video Protection DVP 2.10, 1.40.0.15, 2.10.0.5
Timeline
- 2018-02-01: disclosed: Vulnerability discovered by Zero Science Lab
- 2018-04-02: advisory: Exploit-DB entry published
- 2026-04-29: advisory: NVD/VulnCheck advisory published