CVE-2023-47213
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
Published:Nov 16, 2023
Last Modified:Nov 21, 2024
EPS:Nov 16, 2023
EPSS Score:0.01379
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
C-first
Product
Cfr-1004ea
C-first
Cfr-1004ea
Vendor
C-first
Product
Cfr-1004ea Firmware
C-first
Cfr-1004ea Firmware
Vendor
C-first
Product
Cfr-1008ea
C-first
Cfr-1008ea
Vendor
C-first
Product
Cfr-1008ea Firmware
C-first
Cfr-1008ea Firmware
Vendor
C-first
Product
Cfr-1016ea
C-first
Cfr-1016ea
Vendor
C-first
Product
Cfr-1016ea Firmware
C-first
Cfr-1016ea Firmware
Vendor
C-first
Product
Cfr-16eaa
C-first
Cfr-16eaa
Vendor
C-first
Product
Cfr-16eaa Firmware
C-first
Cfr-16eaa Firmware
Vendor
C-first
Product
Cfr-16eab
C-first
Cfr-16eab
Vendor
C-first
Product
Cfr-16eab Firmware
C-first
Cfr-16eab Firmware
Vendor
C-first
Product
Cfr-16eha
C-first
Cfr-16eha
Vendor
C-first
Product
Cfr-16eha Firmware
C-first
Cfr-16eha Firmware
Vendor
C-first
Product
Cfr-16ehd
C-first
Cfr-16ehd
Vendor
C-first
Product
Cfr-16ehd Firmware
C-first
Cfr-16ehd Firmware
Vendor
C-first
Product
Cfr-4eaa
C-first
Cfr-4eaa
Vendor
C-first
Product
Cfr-4eaa Firmware
C-first
Cfr-4eaa Firmware
Vendor
C-first
Product
Cfr-4eaam
C-first
Cfr-4eaam
Vendor
C-first
Product
Cfr-4eaam Firmware
C-first
Cfr-4eaam Firmware
Vendor
C-first
Product
Cfr-4eab
C-first
Cfr-4eab
Vendor
C-first
Product
Cfr-4eab Firmware
C-first
Cfr-4eab Firmware
Vendor
C-first
Product
Cfr-4eabc
C-first
Cfr-4eabc
Vendor
C-first
Product
Cfr-4eabc Firmware
C-first
Cfr-4eabc Firmware
Vendor
C-first
Product
Cfr-4eha
C-first
Cfr-4eha
Vendor
C-first
Product
Cfr-4eha Firmware
C-first
Cfr-4eha Firmware
Vendor
C-first
Product
Cfr-4ehd
C-first
Cfr-4ehd
Vendor
C-first
Product
Cfr-4ehd Firmware
C-first
Cfr-4ehd Firmware
Vendor
C-first
Product
Cfr-8eaa
C-first
Cfr-8eaa
Vendor
C-first
Product
Cfr-8eaa Firmware
C-first
Cfr-8eaa Firmware
Vendor
C-first
Product
Cfr-8eab
C-first
Cfr-8eab
Vendor
C-first
Product
Cfr-8eab Firmware
C-first
Cfr-8eab Firmware
Vendor
C-first
Product
Cfr-8eha
C-first
Cfr-8eha
Vendor
C-first
Product
Cfr-8eha Firmware
C-first
Cfr-8eha Firmware
Vendor
C-first
Product
Cfr-8ehd
C-first
Cfr-8ehd
Vendor
C-first
Product
Cfr-8ehd Firmware
C-first
Cfr-8ehd Firmware
Vendor
C-first
Product
Cfr-904e
C-first
Cfr-904e
Vendor
C-first
Product
Cfr-904e Firmware
C-first
Cfr-904e Firmware
Vendor
C-first
Product
Cfr-908e
C-first
Cfr-908e
Vendor
C-first
Product
Cfr-908e Firmware
C-first
Cfr-908e Firmware
Vendor
C-first
Product
Cfr-916e
C-first
Cfr-916e
Vendor
C-first
Product
Cfr-916e Firmware
C-first
Cfr-916e Firmware
Vendor
C-first
Product
Md-404aa
C-first
Md-404aa
Vendor
C-first
Product
Md-404aa Firmware
C-first
Md-404aa Firmware
Vendor
C-first
Product
Md-404ab
C-first
Md-404ab
Vendor
C-first
Product
Md-404ab Firmware
C-first
Md-404ab Firmware
Vendor
C-first
Product
Md-404ha
C-first
Md-404ha
Vendor
C-first
Product
Md-404ha Firmware
C-first
Md-404ha Firmware
Vendor
C-first
Product
Md-404hd
C-first
Md-404hd
Vendor
C-first
Product
Md-404hd Firmware
C-first
Md-404hd Firmware
Vendor
C-first
Product
Md-808aa
C-first
Md-808aa
Vendor
C-first
Product
Md-808aa Firmware
C-first
Md-808aa Firmware
Vendor
C-first
Product
Md-808ab
C-first
Md-808ab
Vendor
C-first
Product
Md-808ab Firmware
C-first
Md-808ab Firmware
Vendor
C-first
Product
Md-808ha
C-first
Md-808ha
Vendor
C-first
Product
Md-808ha Firmware
C-first
Md-808ha Firmware
Vendor
C-first
Product
Md-808hd
C-first
Md-808hd
Vendor
C-first
Product
Md-808hd Firmware
C-first
Md-808hd Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
