CVE-2023-47674
Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- c-first/cfr-1004ea firmware · c-first/cfr-1008ea firmware · c-first/cfr-1016ea firmware · c-first/cfr-16eaa firmware · c-first/cfr-16eab firmware · c-first/cfr-16eha firmware · c-first/cfr-16ehd firmware · c-first/cfr-4eaa firmware · c-first/cfr-4eaam firmware · c-first/cfr-4eab firmware · c-first/cfr-4eabc firmware · c-first/cfr-4eha firmware · c-first/cfr-4ehd firmware · c-first/cfr-8eaa firmware · c-first/cfr-8eab firmware · c-first/cfr-8eha firmware · c-first/cfr-8ehd firmware · c-first/cfr-904e firmware · c-first/cfr-908e firmware · c-first/cfr-916e firmware · +8 more
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/vu/JVNVU99077347/Third Party Advisory
- https://www.c-first.co.jp/information/ddososhirase/Vendor Advisory
- https://www.c-first.co.jp/wp/wp-content/uploads/2023/11/tuushin.pdfVendor Advisory
- https://jvn.jp/en/vu/JVNVU99077347/Third Party Advisory
- https://www.c-first.co.jp/information/ddososhirase/Vendor Advisory
- https://www.c-first.co.jp/wp/wp-content/uploads/2023/11/tuushin.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.