PT-2019-8603 · Hanwha Techwin · Srn-4000

Publicado

2019-04-08

·

Atualizado

2019-10-09

·

CVE-2017-7912

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hanwha Techwin SRN-4000 versions prior to SRN4000 v2.16 170401
Description A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.
Recommendations For versions prior to SRN4000 v2.16 170401, update the firmware to SRN4000 v2.16 170401 or later to resolve the issue.

Correção

Improper Access Control

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7912

Produtos afetados

Srn-4000