Vulnerability Description
In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a Sudo misconfiguration.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qvis | Dvr Firmware | < 2021-12-13 |
| Qvis | Dvr | - |
| Qvis | Nvr Firmware | < 2021-12-13 |
| Qvis | Nvr | - |
References
- https://gist.github.com/Meeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee/a670418d51051d4e65Third Party Advisory
- https://twitter.com/Me9187/status/1414906288287404039ExploitThird Party Advisory
- https://gist.github.com/Meeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee/a670418d51051d4e65Third Party Advisory
- https://twitter.com/Me9187/status/1414906288287404039ExploitThird Party Advisory
FAQ
What is CVE-2021-44954?
CVE-2021-44954 is a vulnerability with a CVSS score of 7.8 (HIGH). In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a Sudo misconfiguration.
How severe is CVE-2021-44954?
CVE-2021-44954 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44954?
Check the references section above for vendor advisories and patch information. Affected products include: Qvis Dvr Firmware, Qvis Dvr, Qvis Nvr Firmware, Qvis Nvr.