Fiche vulnérabilité
CVE-2023-47213 : faille critique c-first cfr-1004ea firmware (CVSS 9.8)
Description
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 16 nov. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- c-first cfr-1004ea firmware
- c-first cfr-1008ea firmware
- c-first cfr-1016ea firmware
- c-first cfr-16eaa firmware
- c-first cfr-16eab firmware
- c-first cfr-16eha firmware
- c-first cfr-16ehd firmware
- c-first cfr-4eaa firmware
- c-first cfr-4eaam firmware
- c-first cfr-4eab firmware
- c-first cfr-4eabc firmware
- c-first cfr-4eha firmware
- c-first cfr-4ehd firmware
- c-first cfr-8eaa firmware
- c-first cfr-8eab firmware
- c-first cfr-8eha firmware
- c-first cfr-8ehd firmware
- c-first cfr-904e firmware
- c-first cfr-908e firmware
- c-first cfr-916e firmware