Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-17-136-03 | US Government Resource Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2019-04-08 08:29
Updated : 2019-10-09 16:29
NVD link : CVE-2017-7912
Mitre link : CVE-2017-7912
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
hanwhasecurity
- srn-4000_firmware
- srn-4000