Vulnerability Description
On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Srn 1670D Firmware | - |
| Samsung | Srn 1670D | - |
| Samsung | Srn 1000 Firmware | - |
| Samsung | Srn 1000 | - |
| Samsung | Srn 472S Firmware | - |
| Samsung | Srn 472S | - |
| Samsung | Srn 470D Firmware | - |
| Samsung | Srn 470D | - |
Related Weaknesses (CWE)
References
- https://github.com/zzz66686/Samsung_NVR_vulThird Party Advisory
- https://github.com/zzz66686/Samsung_NVR_vulThird Party Advisory
FAQ
What is CVE-2017-14262?
CVE-2017-14262 is a vulnerability with a CVSS score of 8.1 (HIGH). On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUse...
How severe is CVE-2017-14262?
CVE-2017-14262 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14262?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung Srn 1670D Firmware, Samsung Srn 1670D, Samsung Srn 1000 Firmware, Samsung Srn 1000, Samsung Srn 472S Firmware.