Description
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
Published: 2018-06-14
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-3708 Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
History

No history.

Subscriptions

Hanwha-security Hrd-1641 Hrd-1641 Firmware Hrd-1642 Hrd-1642 Firmware Hrd-440 Hrd-440 Firmware Hrd-442 Hrd-442 Firmware Hrd-443 Hrd-443 Firmware Hrd-840 Hrd-840 Firmware Hrd-841 Hrd-841 Firmware Hrd-842 Hrd-842 Firmware Srd-1694u Srd-1694u Firmware
Samsung Smartviewer
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T08:17:08.457Z

Reserved: 2018-06-03T00:00:00.000Z

Link: CVE-2018-11689

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-14T20:29:00.317

Modified: 2024-11-21T03:43:49.723

Link: CVE-2018-11689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses