Vulnerability Description
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Smartviewer | - |
| Hanwha-Security | Hrd-1642 Firmware | <= 1.16 |
| Hanwha-Security | Hrd-1642 | - |
| Hanwha-Security | Hrd-842 Firmware | <= 1.16 |
| Hanwha-Security | Hrd-842 | - |
| Hanwha-Security | Hrd-442 Firmware | <= 1.16 |
| Hanwha-Security | Hrd-442 | - |
| Hanwha-Security | Hrd-1641 Firmware | <= 1.14 |
| Hanwha-Security | Hrd-1641 | - |
| Hanwha-Security | Hrd-841 Firmware | <= 1.14 |
| Hanwha-Security | Hrd-841 | - |
| Hanwha-Security | Hrd-840 Firmware | <= 1.14 |
| Hanwha-Security | Hrd-840 | - |
| Hanwha-Security | Hrd-440 Firmware | <= 1.14 |
| Hanwha-Security | Hrd-440 | - |
| Hanwha-Security | Hrd-443 Firmware | <= 1.14 |
| Hanwha-Security | Hrd-443 | - |
| Hanwha-Security | Srd-1694U Firmware | <= 1.14 |
| Hanwha-Security | Srd-1694U | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/542083/100/0/threadedExploitThird Party AdvisoryVDB Entry
- https://drive.google.com/file/d/1aWbvdrx1KRkUv4ikkm530a2N5qrxCLmr/view?usp=shariExploitThird Party Advisory
- https://seclists.org/bugtraq/2018/Jun/40ExploitMailing ListThird Party Advisory
- https://vulmon.com/vulnerabilitydetails?qid=CVE-2018-11689Third Party Advisory
- http://www.securityfocus.com/archive/1/542083/100/0/threadedExploitThird Party AdvisoryVDB Entry
- https://drive.google.com/file/d/1aWbvdrx1KRkUv4ikkm530a2N5qrxCLmr/view?usp=shariExploitThird Party Advisory
- https://seclists.org/bugtraq/2018/Jun/40ExploitMailing ListThird Party Advisory
- https://vulmon.com/vulnerabilitydetails?qid=CVE-2018-11689Third Party Advisory
FAQ
What is CVE-2018-11689?
CVE-2018-11689 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was tra...
How severe is CVE-2018-11689?
CVE-2018-11689 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11689?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung Smartviewer, Hanwha-Security Hrd-1642 Firmware, Hanwha-Security Hrd-1642, Hanwha-Security Hrd-842 Firmware, Hanwha-Security Hrd-842.