Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. If an attacker does not enter any value for a specific URL parameter, NULL pointer references will occur and the NVR will reboot. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 24 Dec 2024 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. If an attacker does not enter any value for a specific URL parameter, NULL pointer references will occur and the NVR will reboot. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds. | |
Title | Null Pointer Dereference | |
Weaknesses | CWE-476 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Hanwha_Vision
Published: 2024-12-24T05:30:41.603Z
Updated: 2024-12-24T15:24:24.167Z
Reserved: 2024-07-23T00:24:03.861Z
Link: CVE-2024-41884

Updated: 2024-12-24T15:24:20.503Z

Status : Received
Published: 2024-12-24T06:15:34.060
Modified: 2024-12-24T06:15:34.060
Link: CVE-2024-41884

No data.