The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.
Successful exploitation of this vulnerability could allow the remote attacker to change system time of the targeted device.
References
Link | Resource |
---|---|
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0240 | Vendor Advisory |
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0240 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
History
21 Nov 2024, 08:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0240 - Vendor Advisory |
01 Sep 2023, 17:12
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:cpplusworld:cp-uvr-1601e1-h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cpplusworld:cp-uvr-1601e2-h:-:*:*:*:*:*:*:* cpe:2.3:o:cpplusworld:cp-uvr-0801f1-hc_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cpplusworld:cp-uvr-1601e1-h:-:*:*:*:*:*:*:* cpe:2.3:o:cpplusworld:cp-uvr-0801k1-h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cpplusworld:cp-uvr-0801k1-h:-:*:*:*:*:*:*:* cpe:2.3:o:cpplusworld:cp-uvr-0808k1-h_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:cpplusworld:cp-uvr-0401l1-4kh_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cpplusworld:cp-uvr-0808k1-h:-:*:*:*:*:*:*:* cpe:2.3:h:cpplusworld:cp-uvr-0401l1b-4kh:-:*:*:*:*:*:*:* cpe:2.3:h:cpplusworld:cp-uvr-0801k1b-h:-:*:*:*:*:*:*:* cpe:2.3:o:cpplusworld:cp-uvr-1601e2-h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cpplusworld:cp-uvr-0401l1-4kh:-:*:*:*:*:*:*:* cpe:2.3:o:cpplusworld:cp-uvr-0401l1b-4kh_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cpplusworld:cp-uvr-0801f1-hc:-:*:*:*:*:*:*:* cpe:2.3:o:cpplusworld:cp-uvr-0801k1b-h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:cpplusworld:cp-uvr-1601e1-hc:-:*:*:*:*:*:*:* cpe:2.3:o:cpplusworld:cp-uvr-1601e1-hc_firmware:*:*:*:*:*:*:*:* |
|
References | (MISC) https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0240 - Vendor Advisory | |
First Time |
Cpplusworld cp-uvr-1601e1-h Firmware
Cpplusworld cp-uvr-1601e2-h Cpplusworld cp-uvr-0801k1b-h Cpplusworld Cpplusworld cp-uvr-0401l1b-4kh Firmware Cpplusworld cp-uvr-1601e2-h Firmware Cpplusworld cp-uvr-0808k1-h Cpplusworld cp-uvr-0801f1-hc Cpplusworld cp-uvr-0401l1b-4kh Cpplusworld cp-uvr-0801k1-h Cpplusworld cp-uvr-1601e1-hc Firmware Cpplusworld cp-uvr-0808k1-h Firmware Cpplusworld cp-uvr-1601e1-hc Cpplusworld cp-uvr-1601e1-h Cpplusworld cp-uvr-0401l1-4kh Cpplusworld cp-uvr-0401l1-4kh Firmware Cpplusworld cp-uvr-0801k1-h Firmware Cpplusworld cp-uvr-0801f1-hc Firmware Cpplusworld cp-uvr-0801k1b-h Firmware |
|
CWE | CWE-20 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
24 Aug 2023, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-24 07:15
Updated : 2024-11-21 08:17
NVD link : CVE-2023-3704
Mitre link : CVE-2023-3704
CVE.ORG link : CVE-2023-3704
JSON object : View
Products Affected
cpplusworld
- cp-uvr-0801f1-hc_firmware
- cp-uvr-0401l1-4kh
- cp-uvr-0808k1-h
- cp-uvr-0801k1-h_firmware
- cp-uvr-1601e1-hc_firmware
- cp-uvr-0801k1-h
- cp-uvr-1601e1-hc
- cp-uvr-0401l1b-4kh
- cp-uvr-0801f1-hc
- cp-uvr-1601e2-h_firmware
- cp-uvr-1601e1-h_firmware
- cp-uvr-0801k1b-h_firmware
- cp-uvr-0401l1-4kh_firmware
- cp-uvr-0401l1b-4kh_firmware
- cp-uvr-0801k1b-h
- cp-uvr-1601e1-h
- cp-uvr-1601e2-h
- cp-uvr-0808k1-h_firmware
CWE
CWE-20
Improper Input Validation