Description
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
Published: 2023-11-16
Score: 9.8 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-51345 First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
History

Mon, 21 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

C-first Cfr-1004ea Cfr-1004ea Firmware Cfr-1008ea Cfr-1008ea Firmware Cfr-1016ea Cfr-1016ea Firmware Cfr-16eaa Cfr-16eaa Firmware Cfr-16eab Cfr-16eab Firmware Cfr-16eha Cfr-16eha Firmware Cfr-16ehd Cfr-16ehd Firmware Cfr-4eaa Cfr-4eaa Firmware Cfr-4eaam Cfr-4eaam Firmware Cfr-4eab Cfr-4eab Firmware Cfr-4eabc Cfr-4eabc Firmware Cfr-4eha Cfr-4eha Firmware Cfr-4ehd Cfr-4ehd Firmware Cfr-8eaa Cfr-8eaa Firmware Cfr-8eab Cfr-8eab Firmware Cfr-8eha Cfr-8eha Firmware Cfr-8ehd Cfr-8ehd Firmware Cfr-904e Cfr-904e Firmware Cfr-908e Cfr-908e Firmware Cfr-916e Cfr-916e Firmware Md-404aa Md-404aa Firmware Md-404ab Md-404ab Firmware Md-404ha Md-404ha Firmware Md-404hd Md-404hd Firmware Md-808aa Md-808aa Firmware Md-808ab Md-808ab Firmware Md-808ha Md-808ha Firmware Md-808hd Md-808hd Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-10-21T14:27:58.805Z

Reserved: 2023-11-15T01:42:55.281Z

Link: CVE-2023-47213

cve-icon Vulnrichment

Updated: 2024-08-02T21:01:22.825Z

cve-icon NVD

Status : Modified

Published: 2023-11-16T08:15:32.840

Modified: 2024-11-21T08:29:58.057

Link: CVE-2023-47213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses