CVE-2017-14263: Critical severity honeywell enterprise dvr vulnerability
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14263?
CVE-2017-14263 has been classified as a medium severity vulnerability that affects Honeywell NVR devices.
How do I fix CVE-2017-14263?
To fix CVE-2017-14263, ensure that you update the affected Honeywell NVR firmware to the latest version provided by Honeywell.
Which devices are affected by CVE-2017-14263?
CVE-2017-14263 affects specific Honeywell NVR devices including those with Enterprise DVR, Maxpro NVR Hybrid SE, XE, and other related firmware versions.
What type of attack does CVE-2017-14263 enable?
CVE-2017-14263 enables remote attackers to create unauthorized user accounts with admin privileges on vulnerable Honeywell NVR devices.
Can CVE-2017-14263 be exploited without physical access?
Yes, CVE-2017-14263 can be exploited remotely by leveraging access to a guest account.