Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Takenaka Engineering
Takenaka Engineering ahd04t-a Firmware Takenaka Engineering ahd08t-a Firmware Takenaka Engineering ahd16t-a Firmware Takenaka Engineering hdvr-1600 Firmware Takenaka Engineering hdvr-400 Firmware Takenaka Engineering hdvr-800 Firmware Takenaka Engineering nvr04t-a Firmware Takenaka Engineering nvr08t-a Firmware Takenaka Engineering nvr16t-a Firmware |
|
Weaknesses | CWE-287 | |
CPEs | cpe:2.3:o:takenaka_engineering:ahd04t-a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:takenaka_engineering:ahd08t-a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:takenaka_engineering:ahd16t-a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:takenaka_engineering:hdvr-1600_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:takenaka_engineering:hdvr-400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:takenaka_engineering:hdvr-800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:takenaka_engineering:nvr04t-a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:takenaka_engineering:nvr08t-a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:takenaka_engineering:nvr16t-a_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Takenaka Engineering
Takenaka Engineering ahd04t-a Firmware Takenaka Engineering ahd08t-a Firmware Takenaka Engineering ahd16t-a Firmware Takenaka Engineering hdvr-1600 Firmware Takenaka Engineering hdvr-400 Firmware Takenaka Engineering hdvr-800 Firmware Takenaka Engineering nvr04t-a Firmware Takenaka Engineering nvr08t-a Firmware Takenaka Engineering nvr16t-a Firmware |
|
Metrics |
cvssV3_1
|
Wed, 18 Sep 2024 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: jpcert
Published: 2024-09-18T06:07:55.880Z
Updated: 2024-09-18T15:23:55.272Z
Reserved: 2024-09-17T04:33:43.397Z
Link: CVE-2024-41929
Vulnrichment
Updated: 2024-09-18T15:00:21.367Z
NVD
Status : Awaiting Analysis
Published: 2024-09-18T07:15:02.847
Modified: 2024-09-20T12:30:51.220
Link: CVE-2024-41929
Redhat
No data.