CVE-2023-3705: Information Disclosure Vulnerability in CP-Plus Network Video Recorder
The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.
Successful exploitation of this vulnerability could allow the remote attacker to obtain sensitive information on the targeted device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3705?
CVE-2023-3705 is classified as a medium severity vulnerability due to its potential for unauthorized remote exploitation.
How do I fix CVE-2023-3705?
To remediate CVE-2023-3705, update the CP Plus firmware to version b3223p22c02424 or later.
Who is affected by CVE-2023-3705?
CVE-2023-3705 affects users of the CP Plus NVR models CP-VNR-3104, CP-VNR-3108, and CP-VNR-3208 with specific outdated firmware.
What type of vulnerability is CVE-2023-3705?
CVE-2023-3705 is an improper input handling vulnerability that can be exploited via specially crafted HTTP requests.
Is CVE-2023-3705 exploitable without authentication?
Yes, CVE-2023-3705 can be exploited by unauthenticated remote attackers.