7.5
CVE-2013-1391
- EPSS 87.15%
- Veröffentlicht 30.10.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:49:29
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huntcctv ≫ Dvr-04ch Firmware Version-
Huntcctv ≫ Dvr-04nc Firmware Version-
Huntcctv ≫ Dvr-08ch Firmware Version-
Huntcctv ≫ Dvr-08nc Firmware Version-
Huntcctv ≫ Dvr-16ch Firmware Version-
Huntcctv ≫ Dr6-704a4h Firmware Version-
Huntcctv ≫ Dr6-708a4h Firmware Version-
Huntcctv ≫ Dr6-7316a4h Firmware Version-
Huntcctv ≫ Dr6-7316a4hl Firmware Version-
Huntcctv ≫ Hdr-04kd Firmware Version-
Huntcctv ≫ Hdr-08kd Firmware Version-
Capturecctv ≫ Cdr 0410ve Firmware Version-
Capturecctv ≫ Cdr 0820vde Firmware Version-
Hachi ≫ Hv-04rd Pro Firmware Version-
Hachi ≫ Hv-08rd Pro Firmware Version-
Novuscctv ≫ Nv-dvr1204 Firmware Version-
Novuscctv ≫ Nv-dvr1208 Firmware Version-
Novuscctv ≫ Nv-dvr1216 Firmware Version-
Vsp ≫ Tw-dvr604 Firmware Version-
Vsp ≫ Tw-dvr616 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 87.15% | 0.994 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.