CVE-2023-7227
SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.28% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- systemk-corp/nvr 504 firmware · systemk-corp/nvr 508 firmware · systemk-corp/nvr 516 firmware
- Source
- ics-cert@hq.dhs.gov
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-025-02Third Party Advisory, US Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-025-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.