Description
An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device.
Published: 2019-09-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-3868 An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device.
History

No history.

Subscriptions

Hanwha-security Srn-1673s Srn-1673s Firmware Srn-472s Srn-472s Firmware Srn-873s Srn-873s Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T23:17:38.922Z

Reserved: 2019-05-20T00:00:00.000Z

Link: CVE-2019-12223

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-05T15:15:11.783

Modified: 2024-11-21T04:22:27.613

Link: CVE-2019-12223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses