SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-47213

First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device.

CRITICAL 9.8EPSS 1.09%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.09% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-798
Affected
c-first/cfr-1004ea firmware · c-first/cfr-1008ea firmware · c-first/cfr-1016ea firmware · c-first/cfr-16eaa firmware · c-first/cfr-16eab firmware · c-first/cfr-16eha firmware · c-first/cfr-16ehd firmware · c-first/cfr-4eaa firmware · c-first/cfr-4eaam firmware · c-first/cfr-4eab firmware · c-first/cfr-4eabc firmware · c-first/cfr-4eha firmware · c-first/cfr-4ehd firmware · c-first/cfr-8eaa firmware · c-first/cfr-8eab firmware · c-first/cfr-8eha firmware · c-first/cfr-8ehd firmware · c-first/cfr-904e firmware · c-first/cfr-908e firmware · c-first/cfr-916e firmware · +8 more
Source
vultures@jpcert.or.jp

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.