Description
Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
Published: 2023-11-16
Score: 9.8 Critical
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-51773 Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
History

Wed, 11 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

C-first Cfr-1004ea Cfr-1004ea Firmware Cfr-1008ea Cfr-1008ea Firmware Cfr-1016ea Cfr-1016ea Firmware Cfr-16eaa Cfr-16eaa Firmware Cfr-16eab Cfr-16eab Firmware Cfr-16eha Cfr-16eha Firmware Cfr-16ehd Cfr-16ehd Firmware Cfr-4eaa Cfr-4eaa Firmware Cfr-4eaam Cfr-4eaam Firmware Cfr-4eab Cfr-4eab Firmware Cfr-4eabc Cfr-4eabc Firmware Cfr-4eha Cfr-4eha Firmware Cfr-4ehd Cfr-4ehd Firmware Cfr-8eaa Cfr-8eaa Firmware Cfr-8eab Cfr-8eab Firmware Cfr-8eha Cfr-8eha Firmware Cfr-8ehd Cfr-8ehd Firmware Cfr-904e Cfr-904e Firmware Cfr-908e Cfr-908e Firmware Cfr-916e Cfr-916e Firmware Md-404aa Md-404aa Firmware Md-404ab Md-404ab Firmware Md-404ha Md-404ha Firmware Md-404hd Md-404hd Firmware Md-808aa Md-808aa Firmware Md-808ab Md-808ab Firmware Md-808ha Md-808ha Firmware Md-808hd Md-808hd Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2025-06-11T14:12:04.230Z

Reserved: 2023-11-15T01:42:54.432Z

Link: CVE-2023-47674

cve-icon Vulnrichment

Updated: 2024-08-02T21:16:43.197Z

cve-icon NVD

Status : Modified

Published: 2023-11-16T08:15:33.147

Modified: 2025-06-11T15:15:27.487

Link: CVE-2023-47674

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses