Multiple vulnerabilities in First Corporation DVRs


Published: 2023-11-27

Security Bulletin


This security bulletin contains information about 2 vulnerabilities.


EUVDB-ID: #VU83491


Risk: High


CVSSv3.1:


CVE-ID: CVE-2023-47213


CWE-ID: CWE-259 - Use of Hard-coded Password


Exploit availability: No


Description

The vulnerability allows a remote attacker to compromise the target system.


The vulnerability exists due to use a hard-coded password. A remote attacker can rewrite or obtain the configuration information of the target device.


Mitigation

Install updates from vendor's website for the following products.


  • CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, MD-808AB

  • Vulnerable software versions

    CFR-904E: All versions


    CFR-908E: All versions


    CFR-916E: All versions


    CFR-4EHD: All versions


    CFR-8EHD: All versions


    CFR-16EHD: All versions


    CFR-4EHA: All versions


    CFR-8EHA: All versions


    CFR-16EHA: All versions


    CFR-4EAAM: All versions


    CFR-4EABC: All versions


    CFR-4EAA: All versions


    CFR-8EAA: All versions


    CFR-16EAA: All versions


    CFR-4EAB: All versions


    CFR-8EAB: All versions


    CFR-16EAB: All versions


    CFR-1004EA: All versions


    CFR-1008EA: All versions


    CFR-1016EA: All versions


    MD-404HD: All versions


    MD-808HD: All versions


    MD-404HA: All versions


    MD-808HA: All versions


    MD-404AA: All versions


    MD-808AA: All versions


    MD-404AB: All versions


    MD-808AB: All versions


    CPE2.3
    ..

    Support the originator by clicking the read the rest link below.