10
CVE-2021-41506
- EPSS 0.98%
- Published 30.06.2022 13:15:08
- Last modified 21.11.2024 06:26:20
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.
Data is provided by the National Vulnerability Database (NVD)
Xiongmaitech ≫ Ahb7008t-mh-v2 Firmware Version4.02.r11.7601.nat.onvif.20170420
Xiongmaitech ≫ Ahb7804r-els Firmware Version4.02.r11.nat.onvif.20160422
Xiongmaitech ≫ Ahb7804r-mh-v2 Firmware Version4.02.r11.7601.nat.onvif.20170424
Xiongmaitech ≫ Ahb7808r-ms-v2 Firmware Version4.02.r11.nat.onvif.20170327
Xiongmaitech ≫ Ahb7808r-ms Firmware Version4.02.r11.nat.onvif.20160328
Xiongmaitech ≫ Ahb7808t-ms-v2 Firmware Version4.02.r11.nat.onvifc.20161205
Xiongmaitech ≫ Ahb7804r-lms Firmware Version4.02.r11.nat.20170301
Xiongmaitech ≫ Hi3518e 50h10l S39 Firmware Version4.02.r12.nat.onvifs.20170727
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.98% | 0.759 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.