PT-2019-8603 · Hanwha Techwin · Srn-4000
Publicado
2019-04-08
·
Atualizado
2019-10-09
·
CVE-2017-7912
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hanwha Techwin SRN-4000 versions prior to SRN4000 v2.16 170401
Description
A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.
Recommendations
For versions prior to SRN4000 v2.16 170401, update the firmware to SRN4000 v2.16 170401 or later to resolve the issue.
Correção
Improper Access Control
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Srn-4000