CVE-2019-12223
An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device.
Published:Sep 5, 2019
Last Modified:Nov 21, 2024
EPS:Sep 5, 2019
EPSS Score:0.0053
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Hanwha-security
Product
Srn-1673s
Hanwha-security
Srn-1673s
Vendor
Hanwha-security
Product
Srn-1673s Firmware
Hanwha-security
Srn-1673s Firmware
Vendor
Hanwha-security
Product
Srn-472s
Hanwha-security
Srn-472s
Vendor
Hanwha-security
Product
Srn-472s Firmware
Hanwha-security
Srn-472s Firmware
Vendor
Hanwha-security
Product
Srn-873s
Hanwha-security
Srn-873s
Vendor
Hanwha-security
Product
Srn-873s Firmware
Hanwha-security
Srn-873s Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
