Search
Find a vulnerability
Search criteria
8 vulnerabilities by genetec
CVE-2025-1789 (GCVE-0-2025-1789)
Vulnerability from nvd – Published: 2026-02-24 18:47 – Updated: 2026-02-26 14:44
VLAI
EPSS
VEX
Summary
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-02-26 04:56 UTC
CWE
- CWE-276 - Incorrect Default Permissions
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Genetec Inc. | Genetec Update Service |
Affected:
<2.10.600
(semver)
Unaffected: >=2.10.600 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-1789",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-02-26T04:56:04.010019Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-02-26T14:44:07.658Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "Genetec Update Service",
"vendor": "Genetec Inc.",
"versions": [
{
"status": "affected",
"version": "\u003c2.10.600",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=2.10.600",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Rutger Flohil"
}
],
"descriptions": [
{
"lang": "en",
"value": "Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system."
}
],
"impacts": [
{
"capecId": "CAPEC-233",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-233: Privilege Escalation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:H/IR:H/AR:H/MVC:H/MVI:H/MVA:H/MSI:H/MSA:H/S:P/AU:N/V:C",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-276",
"description": "Incorrect Default Permissions",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-02-24T18:47:24.913Z",
"orgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"shortName": "Genetec"
},
"references": [
{
"url": "https://techdocs.genetec.com/r/en-US/Security-Updates-for-GenetecTM-Update-Service-2.10/Resolved-vulnerabilities-in-Genetec-Update-Service-2.10"
}
],
"solutions": [
{
"lang": "en",
"value": "This issue is fixed in Genetec Update Service 2.10.600 and all later versions. Internet connected Genetec Update Service will automatically update themselves."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"assignerShortName": "Genetec",
"cveId": "CVE-2025-1789",
"datePublished": "2026-02-24T18:47:24.913Z",
"dateReserved": "2025-02-28T17:07:08.574Z",
"dateUpdated": "2026-02-26T14:44:07.658Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-1787 (GCVE-0-2025-1787)
Vulnerability from nvd – Published: 2026-02-24 18:44 – Updated: 2026-02-26 14:44
VLAI
EPSS
VEX
Summary
Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows user could exploit this vulnerability to gain elevated privileges in the Genetec Update Service. Could be combined with CVE-2025-1789 to achieve low privilege escalation.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-02-26 04:56 UTC
CWE
- CWE-346 - Origin Validation Error
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Genetec Inc. | Genetec Update Service |
Affected:
<2.10.600
(semver)
Unaffected: >=2.10.600 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-1787",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-02-26T04:56:05.875817Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-02-26T14:44:07.839Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "Genetec Update Service",
"vendor": "Genetec Inc.",
"versions": [
{
"status": "affected",
"version": "\u003c2.10.600",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=2.10.600",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Rutger Flohil"
}
],
"descriptions": [
{
"lang": "en",
"value": "Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows user could exploit this vulnerability to gain elevated privileges in the Genetec Update Service. Could be combined with CVE-2025-1789 to achieve low privilege escalation."
}
],
"impacts": [
{
"capecId": "CAPEC-200",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-200: Removal of filters: Input filters, output filters, data masking"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:H/IR:H/AR:H/MVC:H/MVI:H/MVA:H/MSI:H/MSA:H/S:P/AU:N/V:C",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-346",
"description": "CWE-346: Origin Validation Error",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-02-24T18:44:36.705Z",
"orgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"shortName": "Genetec"
},
"references": [
{
"url": "https://techdocs.genetec.com/r/en-US/Security-Updates-for-GenetecTM-Update-Service-2.10/Resolved-vulnerabilities-in-Genetec-Update-Service-2.10"
}
],
"solutions": [
{
"lang": "en",
"value": "This issue is fixed in Genetec Update Service 2.10.600 and all later versions. Internet connected Genetec Update Service will automatically update themselves."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"assignerShortName": "Genetec",
"cveId": "CVE-2025-1787",
"datePublished": "2026-02-24T18:44:36.705Z",
"dateReserved": "2025-02-28T17:05:57.628Z",
"dateUpdated": "2026-02-26T14:44:07.839Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-7059 (GCVE-0-2024-7059)
Vulnerability from nvd – Published: 2024-11-05 13:13 – Updated: 2024-11-09 22:45
VLAI
EPSS
VEX
Summary
A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-05 15:06 UTC
CWE
- CWE-470 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Genetec Inc. | Genetec Security Center |
Affected:
<5.8.2.1
(semver)
Unaffected: >=5.8.2.1 (semver) Affected: >=5.9.0.0 <5.9.5.8 (semver) Unaffected: >=5.9.5.8 (semver) Affected: >=5.10.0.0 <5.10.4.23 (semver) Unaffected: >=5.10.4.23 (semver) Affected: >=5.11.0.0 <5.11.3.13 (semver) Unaffected: >=5.11.3.13 (semver) Affected: >=5.12.0.0 <5.12.1.3 (semver) Unaffected: >=5.12.1.3 <5.12.2.0 (semver) Affected: >=5.12.2.0 <5.12.2.1 (semver) Unaffected: >=5.12.2.1 (semver) |
|
| genetec | security_center |
Affected:
0 , < 5.8.2.1
(semver)
Affected: 5.9.0.0 , < 5.9.5.8 (semver) Affected: 5.10.0.0 , < 5.10.4.23 (semver) Affected: 5.11.0.0 , < 5.11.3.13 (semver) Affected: 5.12.0.0 , < 5.12.1.3 (semver) Affected: 5.12.2.0 , < 5.12.2.1 (semver) cpe:2.3:a:genetec:security_center:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:genetec:security_center:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"product": "security_center",
"vendor": "genetec",
"versions": [
{
"lessThan": "5.8.2.1",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "5.9.5.8",
"status": "affected",
"version": "5.9.0.0",
"versionType": "semver"
},
{
"lessThan": "5.10.4.23",
"status": "affected",
"version": "5.10.0.0",
"versionType": "semver"
},
{
"lessThan": "5.11.3.13",
"status": "affected",
"version": "5.11.0.0",
"versionType": "semver"
},
{
"lessThan": "5.12.1.3",
"status": "affected",
"version": "5.12.0.0",
"versionType": "semver"
},
{
"lessThan": "5.12.2.1",
"status": "affected",
"version": "5.12.2.0",
"versionType": "semver"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-7059",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-05T15:06:17.075211Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-11-05T15:11:38.336Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "Genetec Security Center",
"vendor": "Genetec Inc.",
"versions": [
{
"status": "affected",
"version": "\u003c5.8.2.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.8.2.1",
"versionType": "semver"
},
{
"status": "affected",
"version": "\u003e=5.9.0.0 \u003c5.9.5.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.9.5.8",
"versionType": "semver"
},
{
"status": "affected",
"version": "\u003e=5.10.0.0 \u003c5.10.4.23",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.10.4.23",
"versionType": "semver"
},
{
"status": "affected",
"version": "\u003e=5.11.0.0 \u003c5.11.3.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.11.3.13",
"versionType": "semver"
},
{
"status": "affected",
"version": "\u003e=5.12.0.0 \u003c5.12.1.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.12.1.3 \u003c5.12.2.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "\u003e=5.12.2.0 \u003c5.12.2.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.12.2.1",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "AlgoSecure, Louis Moubinous"
}
],
"descriptions": [
{
"lang": "en",
"value": "A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line."
}
],
"impacts": [
{
"capecId": "CAPEC-138",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-138: Reflection Injection"
}
]
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.0"
},
"cvssV3_1": {
"baseScore": 8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"cvssV4_0": {
"baseScore": 8.9,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-470",
"description": "CWE-470 Use of Externally-Controlled Input to Select Classes or Code (\u0027Unsafe Reflection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-09T22:45:41.270Z",
"orgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"shortName": "Genetec"
},
"references": [
{
"url": "https://resources.genetec.com/security-advisories/high-severity-vulnerability-affecting-security-center-web-sdk-role"
},
{
"url": "https://ressources.genetec.com/bulletins-de-securite/vulnerabilite-de-haute-severite-affectant-le-role-sdk-web-de-security-center"
}
],
"solutions": [
{
"lang": "en",
"value": "This issue is fixed in Security Center 5.8.2.1, 5.9.5.8, 5.10.4.23, 5.11.3.13, 5.12.1.3, 5.12.2.1 and all later versions."
}
],
"workarounds": [
{
"lang": "en",
"value": "If the Security Center instance cannot be updated in a timely fashion, the system administrator should deactivate the Web-based SDK role."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"assignerShortName": "Genetec",
"cveId": "CVE-2024-7059",
"datePublished": "2024-11-05T13:13:29.839Z",
"dateReserved": "2024-07-23T20:53:20.464Z",
"dateUpdated": "2024-11-09T22:45:41.270Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-1522 (GCVE-0-2023-1522)
Vulnerability from nvd – Published: 2023-04-05 18:51 – Updated: 2025-02-12 15:45
VLAI
EPSS
VEX
Summary
SQL Injection in the Hardware Inventory report of Security Center 5.11.2.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-02-12 15:41 UTC
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Genetec Inc. | Genetec Security Center |
Affected:
5.11.2
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:49:11.692Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.genetec.com/blog/data-protection/high-severity-vulnerability-affecting-the-hardware-inventory-report-task-of-security-center"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2023-1522",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-02-12T15:41:57.240276Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-02-12T15:45:26.199Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Genetec Security Center",
"vendor": "Genetec Inc.",
"versions": [
{
"status": "affected",
"version": "5.11.2"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SQL Injection in the Hardware Inventory report of Security Center 5.11.2."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-89 SQL Injection",
"lang": "en"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-04-05T18:51:02.590Z",
"orgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"shortName": "Genetec"
},
"references": [
{
"url": "https://www.genetec.com/blog/data-protection/high-severity-vulnerability-affecting-the-hardware-inventory-report-task-of-security-center"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"assignerShortName": "Genetec",
"cveId": "CVE-2023-1522",
"datePublished": "2023-04-05T18:51:02.590Z",
"dateReserved": "2023-03-20T16:24:06.438Z",
"dateUpdated": "2025-02-12T15:45:26.199Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2025-1789 (GCVE-0-2025-1789)
Vulnerability from cvelistv5 – Published: 2026-02-24 18:47 – Updated: 2026-02-26 14:44
VLAI
EPSS
VEX
Summary
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-02-26 04:56 UTC
CWE
- CWE-276 - Incorrect Default Permissions
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Genetec Inc. | Genetec Update Service |
Affected:
<2.10.600
(semver)
Unaffected: >=2.10.600 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-1789",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-02-26T04:56:04.010019Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-02-26T14:44:07.658Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "Genetec Update Service",
"vendor": "Genetec Inc.",
"versions": [
{
"status": "affected",
"version": "\u003c2.10.600",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=2.10.600",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Rutger Flohil"
}
],
"descriptions": [
{
"lang": "en",
"value": "Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system."
}
],
"impacts": [
{
"capecId": "CAPEC-233",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-233: Privilege Escalation"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:H/IR:H/AR:H/MVC:H/MVI:H/MVA:H/MSI:H/MSA:H/S:P/AU:N/V:C",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-276",
"description": "Incorrect Default Permissions",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-02-24T18:47:24.913Z",
"orgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"shortName": "Genetec"
},
"references": [
{
"url": "https://techdocs.genetec.com/r/en-US/Security-Updates-for-GenetecTM-Update-Service-2.10/Resolved-vulnerabilities-in-Genetec-Update-Service-2.10"
}
],
"solutions": [
{
"lang": "en",
"value": "This issue is fixed in Genetec Update Service 2.10.600 and all later versions. Internet connected Genetec Update Service will automatically update themselves."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"assignerShortName": "Genetec",
"cveId": "CVE-2025-1789",
"datePublished": "2026-02-24T18:47:24.913Z",
"dateReserved": "2025-02-28T17:07:08.574Z",
"dateUpdated": "2026-02-26T14:44:07.658Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2025-1787 (GCVE-0-2025-1787)
Vulnerability from cvelistv5 – Published: 2026-02-24 18:44 – Updated: 2026-02-26 14:44
VLAI
EPSS
VEX
Summary
Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows user could exploit this vulnerability to gain elevated privileges in the Genetec Update Service. Could be combined with CVE-2025-1789 to achieve low privilege escalation.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-02-26 04:56 UTC
CWE
- CWE-346 - Origin Validation Error
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Genetec Inc. | Genetec Update Service |
Affected:
<2.10.600
(semver)
Unaffected: >=2.10.600 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-1787",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-02-26T04:56:05.875817Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-02-26T14:44:07.839Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "Genetec Update Service",
"vendor": "Genetec Inc.",
"versions": [
{
"status": "affected",
"version": "\u003c2.10.600",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=2.10.600",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Rutger Flohil"
}
],
"descriptions": [
{
"lang": "en",
"value": "Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows user could exploit this vulnerability to gain elevated privileges in the Genetec Update Service. Could be combined with CVE-2025-1789 to achieve low privilege escalation."
}
],
"impacts": [
{
"capecId": "CAPEC-200",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-200: Removal of filters: Input filters, output filters, data masking"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:H/IR:H/AR:H/MVC:H/MVI:H/MVA:H/MSI:H/MSA:H/S:P/AU:N/V:C",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-346",
"description": "CWE-346: Origin Validation Error",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-02-24T18:44:36.705Z",
"orgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"shortName": "Genetec"
},
"references": [
{
"url": "https://techdocs.genetec.com/r/en-US/Security-Updates-for-GenetecTM-Update-Service-2.10/Resolved-vulnerabilities-in-Genetec-Update-Service-2.10"
}
],
"solutions": [
{
"lang": "en",
"value": "This issue is fixed in Genetec Update Service 2.10.600 and all later versions. Internet connected Genetec Update Service will automatically update themselves."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"assignerShortName": "Genetec",
"cveId": "CVE-2025-1787",
"datePublished": "2026-02-24T18:44:36.705Z",
"dateReserved": "2025-02-28T17:05:57.628Z",
"dateUpdated": "2026-02-26T14:44:07.839Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-7059 (GCVE-0-2024-7059)
Vulnerability from cvelistv5 – Published: 2024-11-05 13:13 – Updated: 2024-11-09 22:45
VLAI
EPSS
VEX
Summary
A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-05 15:06 UTC
CWE
- CWE-470 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Genetec Inc. | Genetec Security Center |
Affected:
<5.8.2.1
(semver)
Unaffected: >=5.8.2.1 (semver) Affected: >=5.9.0.0 <5.9.5.8 (semver) Unaffected: >=5.9.5.8 (semver) Affected: >=5.10.0.0 <5.10.4.23 (semver) Unaffected: >=5.10.4.23 (semver) Affected: >=5.11.0.0 <5.11.3.13 (semver) Unaffected: >=5.11.3.13 (semver) Affected: >=5.12.0.0 <5.12.1.3 (semver) Unaffected: >=5.12.1.3 <5.12.2.0 (semver) Affected: >=5.12.2.0 <5.12.2.1 (semver) Unaffected: >=5.12.2.1 (semver) |
|
| genetec | security_center |
Affected:
0 , < 5.8.2.1
(semver)
Affected: 5.9.0.0 , < 5.9.5.8 (semver) Affected: 5.10.0.0 , < 5.10.4.23 (semver) Affected: 5.11.0.0 , < 5.11.3.13 (semver) Affected: 5.12.0.0 , < 5.12.1.3 (semver) Affected: 5.12.2.0 , < 5.12.2.1 (semver) cpe:2.3:a:genetec:security_center:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:genetec:security_center:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"product": "security_center",
"vendor": "genetec",
"versions": [
{
"lessThan": "5.8.2.1",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThan": "5.9.5.8",
"status": "affected",
"version": "5.9.0.0",
"versionType": "semver"
},
{
"lessThan": "5.10.4.23",
"status": "affected",
"version": "5.10.0.0",
"versionType": "semver"
},
{
"lessThan": "5.11.3.13",
"status": "affected",
"version": "5.11.0.0",
"versionType": "semver"
},
{
"lessThan": "5.12.1.3",
"status": "affected",
"version": "5.12.0.0",
"versionType": "semver"
},
{
"lessThan": "5.12.2.1",
"status": "affected",
"version": "5.12.2.0",
"versionType": "semver"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-7059",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-05T15:06:17.075211Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-11-05T15:11:38.336Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows"
],
"product": "Genetec Security Center",
"vendor": "Genetec Inc.",
"versions": [
{
"status": "affected",
"version": "\u003c5.8.2.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.8.2.1",
"versionType": "semver"
},
{
"status": "affected",
"version": "\u003e=5.9.0.0 \u003c5.9.5.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.9.5.8",
"versionType": "semver"
},
{
"status": "affected",
"version": "\u003e=5.10.0.0 \u003c5.10.4.23",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.10.4.23",
"versionType": "semver"
},
{
"status": "affected",
"version": "\u003e=5.11.0.0 \u003c5.11.3.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.11.3.13",
"versionType": "semver"
},
{
"status": "affected",
"version": "\u003e=5.12.0.0 \u003c5.12.1.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.12.1.3 \u003c5.12.2.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "\u003e=5.12.2.0 \u003c5.12.2.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "\u003e=5.12.2.1",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "AlgoSecure, Louis Moubinous"
}
],
"descriptions": [
{
"lang": "en",
"value": "A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line."
}
],
"impacts": [
{
"capecId": "CAPEC-138",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-138: Reflection Injection"
}
]
}
],
"metrics": [
{
"cvssV3_0": {
"baseScore": 8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.0"
},
"cvssV3_1": {
"baseScore": 8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"cvssV4_0": {
"baseScore": 8.9,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-470",
"description": "CWE-470 Use of Externally-Controlled Input to Select Classes or Code (\u0027Unsafe Reflection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-09T22:45:41.270Z",
"orgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"shortName": "Genetec"
},
"references": [
{
"url": "https://resources.genetec.com/security-advisories/high-severity-vulnerability-affecting-security-center-web-sdk-role"
},
{
"url": "https://ressources.genetec.com/bulletins-de-securite/vulnerabilite-de-haute-severite-affectant-le-role-sdk-web-de-security-center"
}
],
"solutions": [
{
"lang": "en",
"value": "This issue is fixed in Security Center 5.8.2.1, 5.9.5.8, 5.10.4.23, 5.11.3.13, 5.12.1.3, 5.12.2.1 and all later versions."
}
],
"workarounds": [
{
"lang": "en",
"value": "If the Security Center instance cannot be updated in a timely fashion, the system administrator should deactivate the Web-based SDK role."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"assignerShortName": "Genetec",
"cveId": "CVE-2024-7059",
"datePublished": "2024-11-05T13:13:29.839Z",
"dateReserved": "2024-07-23T20:53:20.464Z",
"dateUpdated": "2024-11-09T22:45:41.270Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2023-1522 (GCVE-0-2023-1522)
Vulnerability from cvelistv5 – Published: 2023-04-05 18:51 – Updated: 2025-02-12 15:45
VLAI
EPSS
VEX
Summary
SQL Injection in the Hardware Inventory report of Security Center 5.11.2.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2025-02-12 15:41 UTC
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Genetec Inc. | Genetec Security Center |
Affected:
5.11.2
|
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:49:11.692Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.genetec.com/blog/data-protection/high-severity-vulnerability-affecting-the-hardware-inventory-report-task-of-security-center"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2023-1522",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-02-12T15:41:57.240276Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-02-12T15:45:26.199Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Genetec Security Center",
"vendor": "Genetec Inc.",
"versions": [
{
"status": "affected",
"version": "5.11.2"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SQL Injection in the Hardware Inventory report of Security Center 5.11.2."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-89 SQL Injection",
"lang": "en"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-04-05T18:51:02.590Z",
"orgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"shortName": "Genetec"
},
"references": [
{
"url": "https://www.genetec.com/blog/data-protection/high-severity-vulnerability-affecting-the-hardware-inventory-report-task-of-security-center"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "f2b06212-cb4b-41a4-9501-fa2e367495b8",
"assignerShortName": "Genetec",
"cveId": "CVE-2023-1522",
"datePublished": "2023-04-05T18:51:02.590Z",
"dateReserved": "2023-03-20T16:24:06.438Z",
"dateUpdated": "2025-02-12T15:45:26.199Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}