SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-1391

Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.

HIGH 7.5EPSS 76.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 76.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
76.11% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
huntcctv/dvr-04ch firmware · huntcctv/dvr-04nc firmware · huntcctv/dvr-08ch firmware · huntcctv/dvr-08nc firmware · huntcctv/dvr-16ch firmware · huntcctv/dr6-704a4h firmware · huntcctv/dr6-708a4h firmware · huntcctv/dr6-7316a4h firmware · huntcctv/dr6-7316a4hl firmware · huntcctv/hdr-04kd firmware · huntcctv/hdr-08kd firmware · capturecctv/cdr 0410ve firmware · capturecctv/cdr 0820vde firmware · hachi/hv-04rd pro firmware · hachi/hv-08rd pro firmware · novuscctv/nv-dvr1204 firmware · novuscctv/nv-dvr1208 firmware · novuscctv/nv-dvr1216 firmware · vsp/tw-dvr604 firmware · vsp/tw-dvr616 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.