Executive brief
A security vulnerability exists in Genetec Security Center, a platform used for managing physical security systems like video surveillance and access control. An attacker with high-level administrative privileges could exploit this flaw to run unauthorized database commands. This could lead to the theft of sensitive security data, unauthorized modification of access records, or disruption of the security management system.
Technical details
A SQL injection vulnerability (CWE-89) exists within the Access Manager role of Genetec Security Center. The flaw allows an authenticated attacker with high privileges (PR:H) to inject malicious SQL commands through the network. While the attack complexity is rated as high, a successful exploit could result in full compromise of confidentiality, integrity, and availability of the underlying database. The vulnerability has been addressed in Security Center versions 5.12.2.17 and 5.13.3.5.
Affected products
- Genetec Security Center 5.12 prior to 5.12.2.17, 5.13 prior to 5.13.3.5
Timeline
- 2026-05-25: disclosed
- 2026-05-25: advisory
References
- https://techdocs.genetec.com/r/en-US/Security-Updates-for-Security-Center-5.12/Resolved-vulnerabilities-in-Security-Center-5.12.2.17
- https://techdocs.genetec.com/r/en-US/Security-Updates-for-Security-Center-5.13/Resolved-vulnerabilities-in-Security-Center-5.13.3.5
- https://techdocs.genetec.com/r/fr-FR/Mises-a-jour-de-securite-pour-Security-Center-5.12/Vulnerabilites-resolues-dans-Security-Center-5.12.2.17