← Back

CVE-2019-12223

nvd nist
Published: Sep 5, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device.

Affected (3)

3 products
Srn 472s Firmware
Srn 873s Firmware
Srn 1673s Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.07_190502
Running on/withPlatform Versions
Hanwha Security
Srn 472s
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2019-05-03
Running on/withPlatform Versions
Hanwha Security
Srn 873s
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2019-05-03
Running on/withPlatform Versions
Hanwha Security
Srn 1673s
All versions

Timeline

No history available yet.