First published: Mon Sep 11 2017(Updated: )
On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Srn 1670d Firmware | ||
Samsung Srn 1670d | ||
Samsung Srn 1000 Firmware | ||
Samsung Srn 1000 | ||
Samsung Srn 472s Firmware | ||
Samsung Srn 472s | ||
Samsung Srn 470d Firmware | ||
Samsung Srn 470d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.