HIGH · 7.5

CVE-2019-12223

An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long usern...

Vulnerability Description

An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Hanwha-SecuritySrn-472S Firmware1.07_190502
Hanwha-SecuritySrn-472S-
Hanwha-SecuritySrn-873S Firmware< 2019-05-03
Hanwha-SecuritySrn-873S-
Hanwha-SecuritySrn-1673S Firmware< 2019-05-03
Hanwha-SecuritySrn-1673S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-12223?

CVE-2019-12223 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long usern...

How severe is CVE-2019-12223?

CVE-2019-12223 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-12223?

Check the references section above for vendor advisories and patch information. Affected products include: Hanwha-Security Srn-472S Firmware, Hanwha-Security Srn-472S, Hanwha-Security Srn-873S Firmware, Hanwha-Security Srn-873S, Hanwha-Security Srn-1673S Firmware.