VulnerabilityModified
CVE-2013-1391
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.
HIGH 7.5EPSS 76.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 76.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 76.11% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- huntcctv/dvr-04ch firmware · huntcctv/dvr-04nc firmware · huntcctv/dvr-08ch firmware · huntcctv/dvr-08nc firmware · huntcctv/dvr-16ch firmware · huntcctv/dr6-704a4h firmware · huntcctv/dr6-708a4h firmware · huntcctv/dr6-7316a4h firmware · huntcctv/dr6-7316a4hl firmware · huntcctv/hdr-04kd firmware · huntcctv/hdr-08kd firmware · capturecctv/cdr 0410ve firmware · capturecctv/cdr 0820vde firmware · hachi/hv-04rd pro firmware · hachi/hv-08rd pro firmware · novuscctv/nv-dvr1204 firmware · novuscctv/nv-dvr1208 firmware · novuscctv/nv-dvr1216 firmware · vsp/tw-dvr604 firmware · vsp/tw-dvr616 firmware
- Source
- cve@mitre.org
References
- http://www.securitybydefault.com/2013/01/12000-grabadores-de-video-expuestos-en.htmlExploit, Third Party Advisory
- https://www.rapid7.com/db/modules/auxiliary/scanner/misc/dvr_config_disclosureThird Party Advisory
- https://www.securityfocus.com/bid/57579/infoExploit, Third Party Advisory, VDB Entry
- http://www.securitybydefault.com/2013/01/12000-grabadores-de-video-expuestos-en.htmlExploit, Third Party Advisory
- https://www.rapid7.com/db/modules/auxiliary/scanner/misc/dvr_config_disclosureThird Party Advisory
- https://www.securityfocus.com/bid/57579/infoExploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.