PT-2023-30368 · First · Cfr-8Eab+4
Yoshiki Mori
·
Published
2023-11-16
·
Updated
2024-10-21
·
CVE-2023-47213
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
First Corporation's DVRs versions of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB (affected versions not specified, but updates are provided only for Late models)
Description
The issue is related to a hard-coded password in First Corporation's DVRs, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device.
Recommendations
For Late models of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB, apply the available updates.
For other products, apply the provided workaround.
As a temporary workaround, consider restricting access to the device's configuration information until a patch is available.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cfr-16Eab
Cfr-4Eab
Cfr-8Eab
Md-404Ab
Md-808Ab