Vulnerability Description
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| C-First | Cfr-1004Ea Firmware | - |
| C-First | Cfr-1004Ea | - |
| C-First | Cfr-1008Ea Firmware | - |
| C-First | Cfr-1008Ea | - |
| C-First | Cfr-1016Ea Firmware | - |
| C-First | Cfr-1016Ea | - |
| C-First | Cfr-16Eaa Firmware | - |
| C-First | Cfr-16Eaa | - |
| C-First | Cfr-16Eab Firmware | - |
| C-First | Cfr-16Eab | - |
| C-First | Cfr-16Eha Firmware | - |
| C-First | Cfr-16Eha | - |
| C-First | Cfr-16Ehd Firmware | - |
| C-First | Cfr-16Ehd | - |
| C-First | Cfr-4Eaa Firmware | - |
| C-First | Cfr-4Eaa | - |
| C-First | Cfr-4Eaam Firmware | - |
| C-First | Cfr-4Eaam | - |
| C-First | Cfr-4Eab Firmware | - |
| C-First | Cfr-4Eab | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU99077347/Third Party Advisory
- https://www.c-first.co.jp/information/ddososhirase/Vendor Advisory
- https://www.c-first.co.jp/wp/wp-content/uploads/2023/11/tuushin.pdfVendor Advisory
- https://jvn.jp/en/vu/JVNVU99077347/Third Party Advisory
- https://www.c-first.co.jp/information/ddososhirase/Vendor Advisory
- https://www.c-first.co.jp/wp/wp-content/uploads/2023/11/tuushin.pdfVendor Advisory
FAQ
What is CVE-2023-47213?
CVE-2023-47213 is a vulnerability with a CVSS score of 9.8 (CRITICAL). First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are p...
How severe is CVE-2023-47213?
CVE-2023-47213 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-47213?
Check the references section above for vendor advisories and patch information. Affected products include: C-First Cfr-1004Ea Firmware, C-First Cfr-1004Ea, C-First Cfr-1008Ea Firmware, C-First Cfr-1008Ea, C-First Cfr-1016Ea Firmware.