HIGH · 8.1

CVE-2017-14263

Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManag...

Vulnerability Description

Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.

CVSS Score

8.1

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HoneywellEnterprise Dvr Firmware-
HoneywellEnterprise Dvr-
HoneywellMaxpro Nvr Hybrid Se Firmware-
HoneywellMaxpro Nvr Hybrid Se-
HoneywellMaxpro Nvr Hybrid Xe Firmware-
HoneywellMaxpro Nvr Hybrid Xe-
HoneywellMaxpro Nvr Se Firmware-
HoneywellMaxpro Nvr Se-
HoneywellMaxpro Nvr Xe Firmware-
HoneywellMaxpro Nvr Xe-
HoneywellFusion Iv Rev C Firmware-
HoneywellFusion Iv Rev C-
HoneywellMaxpro Nvr Pe Firmware-
HoneywellMaxpro Nvr Pe-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-14263?

CVE-2017-14263 is a vulnerability with a CVSS score of 8.1 (HIGH). Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManag...

How severe is CVE-2017-14263?

CVE-2017-14263 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-14263?

Check the references section above for vendor advisories and patch information. Affected products include: Honeywell Enterprise Dvr Firmware, Honeywell Enterprise Dvr, Honeywell Maxpro Nvr Hybrid Se Firmware, Honeywell Maxpro Nvr Hybrid Se, Honeywell Maxpro Nvr Hybrid Xe Firmware.