9.8

CVE-2023-47213

First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
C-firstCfr-1004ea Firmware Version-
   C-firstCfr-1004ea Version-
C-firstCfr-1008ea Firmware Version-
   C-firstCfr-1008ea Version-
C-firstCfr-1016ea Firmware Version-
   C-firstCfr-1016ea Version-
C-firstCfr-16eaa Firmware Version-
   C-firstCfr-16eaa Version-
C-firstCfr-16eab Firmware Version-
   C-firstCfr-16eab Version-
C-firstCfr-16eha Firmware Version-
   C-firstCfr-16eha Version-
C-firstCfr-16ehd Firmware Version-
   C-firstCfr-16ehd Version-
C-firstCfr-4eaa Firmware Version-
   C-firstCfr-4eaa Version-
C-firstCfr-4eaam Firmware Version-
   C-firstCfr-4eaam Version-
C-firstCfr-4eab Firmware Version-
   C-firstCfr-4eab Version-
C-firstCfr-4eabc Firmware Version-
   C-firstCfr-4eabc Version-
C-firstCfr-4eha Firmware Version-
   C-firstCfr-4eha Version-
C-firstCfr-4ehd Firmware Version-
   C-firstCfr-4ehd Version-
C-firstCfr-8eaa Firmware Version-
   C-firstCfr-8eaa Version-
C-firstCfr-8eab Firmware Version-
   C-firstCfr-8eab Version-
C-firstCfr-8eha Firmware Version-
   C-firstCfr-8eha Version-
C-firstCfr-8ehd Firmware Version-
   C-firstCfr-8ehd Version-
C-firstCfr-904e Firmware Version-
   C-firstCfr-904e Version-
C-firstCfr-908e Firmware Version-
   C-firstCfr-908e Version-
C-firstCfr-916e Firmware Version-
   C-firstCfr-916e Version-
C-firstMd-404aa Firmware Version-
   C-firstMd-404aa Version-
C-firstMd-404ab Firmware Version-
   C-firstMd-404ab Version-
C-firstMd-404ha Firmware Version-
   C-firstMd-404ha Version-
C-firstMd-404hd Firmware Version-
   C-firstMd-404hd Version-
C-firstMd-808aa Firmware Version-
   C-firstMd-808aa Version-
C-firstMd-808ab Firmware Version-
   C-firstMd-808ab Version-
C-firstMd-808ha Firmware Version-
   C-firstMd-808ha Version-
C-firstMd-808hd Firmware Version-
   C-firstMd-808hd Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.38% 0.797
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.