Impact
OpenEye Apex Network Video Recorder firmware implements an administrator password-reset unlock-code process that omits any per-device secret or server‑side cryptographic material. The design allows an attacker who can access the console and the privileged reset workflow to forge a valid unlock code offline. By submitting the forged code, the attacker can reset the system’s administrator password and gain full administrative control of the device. The flaw has existed since at least firmware 2.2.3.4 and persists in the affected 3.2.9.376 release. The underlying weakness is characterized as CWE‑330, improper use of randomness and lack of authentication.
Affected Systems
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 (and all earlier versions lacking the fix) are vulnerable. The vendor recommends upgrading to firmware 3.5.4 to remediate the flaw.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, but physical access to the device is required for exploitation. Because the attacker can forge the unlock code without needing network credentials or remote access, the risk is confined to environments where an attacker can reach the console. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not widely exploited in the wild. Nonetheless, any scenario that allows an attacker to manipulate the password‑reset workflow grants them full administrative privileges and potential lateral movement within the network.
OpenCVE Enrichment