📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global ransomware Multiple sectors CRITICAL 14m Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 1h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 1h Global general Consumer Electronics and Retail MEDIUM 4h Global supply_chain Software Development and Technology HIGH 4h Global general Artificial Intelligence and Software Development LOW 5h Global general Artificial Intelligence and Cybersecurity MEDIUM 5h Global malware Software Development / Technology HIGH 6h Global vulnerability Information Technology HIGH 6h Global data_breach Water Utilities / Critical Infrastructure HIGH 6h Global ransomware Multiple sectors CRITICAL 14m Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 1h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 1h Global general Consumer Electronics and Retail MEDIUM 4h Global supply_chain Software Development and Technology HIGH 4h Global general Artificial Intelligence and Software Development LOW 5h Global general Artificial Intelligence and Cybersecurity MEDIUM 5h Global malware Software Development / Technology HIGH 6h Global vulnerability Information Technology HIGH 6h Global data_breach Water Utilities / Critical Infrastructure HIGH 6h Global ransomware Multiple sectors CRITICAL 14m Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 1h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 1h Global general Consumer Electronics and Retail MEDIUM 4h Global supply_chain Software Development and Technology HIGH 4h Global general Artificial Intelligence and Software Development LOW 5h Global general Artificial Intelligence and Cybersecurity MEDIUM 5h Global malware Software Development / Technology HIGH 6h Global vulnerability Information Technology HIGH 6h Global data_breach Water Utilities / Critical Infrastructure HIGH 6h
Vulnerabilities

CVE-2018-25311

Medium
CWE-22 — Weakness Type
Published: Apr 29, 2026  ·  Modified: May 2, 2026  ·  Source: NVD
CVSS v3
6.5
🔗 NVD Official
📄 Description (English)

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows authenticated attackers to disclose arbitrary files by injecting path traversal sequences in the ID parameter. Attackers can submit requests to downloadsys.pl, download_xml.pl, download.pl, downloadmib.pl, or downloadFile.pl with directory traversal payloads to read sensitive system files like /etc/passwd.

🤖 AI Executive Summary

CVE-2018-25311 is an authenticated directory traversal vulnerability in VideoFlow Digital Video Protection DVP 2.10 that allows attackers with valid credentials to read arbitrary files from the server by manipulating path traversal sequences in the ID parameter. While requiring authentication, this vulnerability poses a significant risk for information disclosure of sensitive system files. No patch is currently available, necessitating immediate compensating controls.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 10, 2026 22:01
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily affects Saudi organizations using VideoFlow DVP 2.10 for digital video protection and content management. Most at-risk sectors include: Government agencies (NCA, Ministry of Interior) managing surveillance systems; Banking sector (SAMA-regulated institutions) using video security; Healthcare facilities (MOH) with video monitoring; Energy sector (ARAMCO, SEC) with critical infrastructure video systems; and Telecommunications (STC, Mobily) managing network security footage. The authenticated nature reduces immediate risk but poses significant insider threat concerns, particularly for organizations with weak access controls or high-privilege user accounts.
🏢 Affected Saudi Sectors
Government Banking Healthcare Energy Telecommunications Security/Surveillance
⚖️ Saudi Risk Score (AI)
6.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Identify all instances of VideoFlow DVP 2.10 in your environment and document their locations and data sensitivity
2. Restrict access to affected systems to only essential personnel with strong authentication requirements
3. Implement network segmentation to isolate VideoFlow systems from critical networks
4. Review and strengthen access control policies for VideoFlow user accounts

Compensating Controls (until patch available):
5. Deploy Web Application Firewall (WAF) rules to block directory traversal patterns (../, ..\ sequences) in ID parameters across all affected endpoints (downloadsys.pl, download_xml.pl, download.pl, downloadmib.pl, downloadFile.pl)
6. Implement input validation and sanitization at the application level to reject path traversal sequences
7. Configure file system permissions to restrict VideoFlow process privileges to only necessary directories
8. Enable comprehensive logging and monitoring of all file access attempts through VideoFlow
9. Conduct regular access reviews of VideoFlow user accounts and disable unused accounts
10. Consider upgrading to a patched version or alternative solution if available

Detection Rules:
- Monitor for requests containing "../" or "..\" in ID parameters to VideoFlow endpoints
- Alert on access attempts to sensitive files (/etc/passwd, /etc/shadow, configuration files) through VideoFlow
- Track failed authentication attempts followed by successful access with directory traversal patterns
- Monitor for unusual file read patterns from VideoFlow process
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حدد جميع حالات VideoFlow DVP 2.10 في بيئتك وقم بتوثيق مواقعها وحساسية البيانات
2. قيد الوصول إلى الأنظمة المتأثرة على الموظفين الأساسيين فقط مع متطلبات مصادقة قوية
3. طبق تقسيم الشبكة لعزل أنظمة VideoFlow عن الشبكات الحرجة
4. راجع وقوي سياسات التحكم في الوصول لحسابات مستخدمي VideoFlow

الضوابط التعويضية (حتى توفر التصحيح):
5. نشر قواعد جدار حماية تطبيقات الويب (WAF) لحجب أنماط اجتياز المجلدات (تسلسلات ../ و ..\ ) في معاملات ID عبر جميع نقاط النهاية المتأثرة
6. طبق التحقق من صحة المدخلات والتنظيف على مستوى التطبيق لرفض تسلسلات اجتياز المسار
7. قم بتكوين أذونات نظام الملفات لتقييد امتيازات عملية VideoFlow على المجلدات الضرورية فقط
8. فعّل التسجيل والمراقبة الشاملة لجميع محاولات الوصول إلى الملفات من خلال VideoFlow
9. أجرِ مراجعات منتظمة لحسابات مستخدمي VideoFlow وعطّل الحسابات غير المستخدمة
10. فكر في الترقية إلى نسخة معدلة أو حل بديل إن أمكن
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Access Control Policy ECC 2024 A.6.1.2 - User Registration and De-registration ECC 2024 A.8.2.1 - User Access Management ECC 2024 A.12.4.1 - Event Logging ECC 2024 A.12.4.3 - Administrator and Operator Logs
🔵 SAMA CSF
ID.AM-2 - Software Inventory PR.AC-1 - Processes and procedures for access management PR.AC-4 - Access rights are managed DE.CM-1 - The network is monitored for unauthorized connections DE.CM-3 - Personnel activity is monitored
🟡 ISO 27001:2022
A.5.1.1 - Policies for information security A.6.1.2 - Information security roles and responsibilities A.8.1.1 - User endpoint devices A.8.2.1 - User registration and access rights A.8.3.1 - Management of privileged access rights A.12.4.1 - Event logging
📊 CVSS Score
6.5
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityN — None / Network
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score6.5
CWECWE-22
EPSS0.37%
Exploit No
Patch ✗ No
Published 2026-04-29
Source Feed nvd
🇸🇦 Saudi Risk Score
6.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-22
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.