PT-2024-5614 · Provision Isr+2 · Sh-8100A-2L+5

Netsecfish

·

Published

2024-08-01

·

Updated

2025-04-08

·

CVE-2024-7339

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions TVT DVR TD-2104TS-CL (affected versions not specified) DVR TD-2108TS-HP (affected versions not specified) Provision-ISR DVR SH-4050A5-5L(MM) (affected versions not specified) AVISION DVR AV108T (affected versions not specified) TD-2116TE-HP (affected versions not specified) SH-8100A-2L(MM) (affected versions not specified)
Description The issue is related to a lack of protection for service data in hybrid HD video recorders, which can be exploited remotely to disclose protected information. The vulnerability affects the /queryDevInfo file and may lead to sensitive data exposure. The exploit has been disclosed to the public and can be used.
Recommendations For TVT DVR TD-2104TS-CL, consider applying restrictive firewalling immediately to minimize the risk of exploitation. For DVR TD-2108TS-HP, consider applying restrictive firewalling immediately to minimize the risk of exploitation. For Provision-ISR DVR SH-4050A5-5L(MM), consider applying restrictive firewalling immediately to minimize the risk of exploitation. For AVISION DVR AV108T, consider applying restrictive firewalling immediately to minimize the risk of exploitation. For TD-2116TE-HP, consider applying restrictive firewalling immediately to minimize the risk of exploitation. For SH-8100A-2L(MM), consider applying restrictive firewalling immediately to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-06307
CVE-2024-7339

Affected Products

Avision Dvr Av108T
Dvr Td-2108Ts-Hp
Provision-Isr Dvr Sh-4050A5-5L
Sh-8100A-2L
Td-2116Te-Hp
Tvt Dvr Td-2104Ts-Cl