Fiche vulnérabilité
CVE-2023-3705 : faille élevée Aditya Infotech Limited CP-VNR-3104… (CVSS 7.5)
Description
The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability could allow the remote attacker to obtain sensitive information on the targeted device.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 24 août 2023
- Dernière mise à jour
- 2 oct. 2024
Produits concernés
- Aditya Infotech Limited CP-VNR-3104, CP-VNR-3108, CP-VNR-3208
Correctif et mesures
Upgrade to the latest firmware B3223P22C02424 https://www.cpplusworld.com/prodassets/firmware/e6428409-e921-4d02-ab19-d35d05aee380.bin https://www.cpplusworld.com/prodassets/firmware/e6428409-e921-4d02-ab19-d35d05aee380.bin