You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
This CVE record has been marked for NVD enrichment efforts.
Description
A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is currently no evidence of active exploitation.
This vulnerability is associated with specific installation package builds rather than the product version identifier alone. Certain versions (including 5.10.4.0, 5.11.3.0, 5.12.2.0 and 5.13.3.0) were released with both vulnerable and remediated installation packages under the same version number.
Consequently, version-based comparison alone is insufficient to determine exposure. Only installations performed using vulnerable builds are affected. Remediated builds can be distinguished using verified installation package hashes. For the complete list of fixed build hashes, refer to the security advisory section.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Title: Genetec Security Center de Genetec, Description: Una vulnerabilidad de alta seguridad que afecta a las instalaciones del servidor principal de Security Center ha sido identificada. Podría permitir a un atacante con privilegios de SO local en el servidor principal acceder a las credenciales de Administrador del Servidor. Un tercero contratado por Genetec encontró el problema. Actualmente no hay evidencia de explotación activa.
Esta vulnerabilidad está asociada con compilaciones de paquetes de instalación específicas en lugar de solo el identificador de versión del producto. Ciertas versiones (incluyendo 5.10.4.0, 5.11.3.0, 5.12.2.0 y 5.13.3.0) fueron lanzadas con paquetes de instalación tanto vulnerables como remediados bajo el mismo número de versión.
En consecuencia, la comparación basada únicamente en la versión es insuficiente para determinar la exposición. Solo las instalaciones realizadas utilizando compilaciones vulnerables están afectadas. Las compilaciones remediadas pueden distinguirse utilizando hashes de paquetes de instalación verificados. Para la lista completa de hashes de compilaciones corregidas, consulte la sección de avisos de seguridad.
New CVE Received from Genetec Inc.6/02/2026 12:16:39 PM
Action
Type
Old Value
New Value
Added
Description
A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is currently no evidence of active exploitation.
This vulnerability is associated with specific installation package builds rather than the product version identifier alone. Certain versions (including 5.10.4.0, 5.11.3.0, 5.12.2.0 and 5.13.3.0) were released with both vulnerable and remediated installation packages under the same version number.
Consequently, version-based comparison alone is insufficient to determine exposure. Only installations performed using vulnerable builds are affected. Remediated builds can be distinguished using verified installation package hashes. For the complete list of fixed build hashes, refer to the security advisory section.