PT-2023-25772 · Unknown · Cp-Plus Nvr

Arko Dhar

+1

·

Published

2023-08-24

·

Updated

2024-10-02

·

CVE-2023-3705

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CP-Plus NVR (affected versions not specified)
Description The issue exists due to improper input handling at the web-based management interface of the affected product. An unauthenticated remote attacker could exploit this by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation could allow the remote attacker to obtain sensitive information on the targeted device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-3705

Affected Products

Cp-Plus Nvr