Description
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
Published: 2023-11-16
Score: 9.8 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-51345 First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
History

Mon, 21 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

C-first Cfr-1004ea Cfr-1004ea Firmware Cfr-1008ea Cfr-1008ea Firmware Cfr-1016ea Cfr-1016ea Firmware Cfr-16eaa Cfr-16eaa Firmware Cfr-16eab Cfr-16eab Firmware Cfr-16eha Cfr-16eha Firmware Cfr-16ehd Cfr-16ehd Firmware Cfr-4eaa Cfr-4eaa Firmware Cfr-4eaam Cfr-4eaam Firmware Cfr-4eab Cfr-4eab Firmware Cfr-4eabc Cfr-4eabc Firmware Cfr-4eha Cfr-4eha Firmware Cfr-4ehd Cfr-4ehd Firmware Cfr-8eaa Cfr-8eaa Firmware Cfr-8eab Cfr-8eab Firmware Cfr-8eha Cfr-8eha Firmware Cfr-8ehd Cfr-8ehd Firmware Cfr-904e Cfr-904e Firmware Cfr-908e Cfr-908e Firmware Cfr-916e Cfr-916e Firmware Md-404aa Md-404aa Firmware Md-404ab Md-404ab Firmware Md-404ha Md-404ha Firmware Md-404hd Md-404hd Firmware Md-808aa Md-808aa Firmware Md-808ab Md-808ab Firmware Md-808ha Md-808ha Firmware Md-808hd Md-808hd Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-10-21T14:27:58.805Z

Reserved: 2023-11-15T01:42:55.281Z

Link: CVE-2023-47213

cve-icon Vulnrichment

Updated: 2024-08-02T21:01:22.825Z

cve-icon NVD

Status : Modified

Published: 2023-11-16T08:15:32.840

Modified: 2024-11-21T08:29:58.057

Link: CVE-2023-47213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses