CVE-2023-3749: VideoEdge config
Published Aug 3, 2023
·Updated
A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
Affected Software
2 affected componentsFixes available
Johnsoncontrols Videoedge<6.1.1
Sensormatic Electronics, LLC, a subsidiary of Johnson Controls Inc. VideoEdge<6.1.1
6.1.1
Remediation
Information
Update VideoEdge to version 6.1.1.
The update can be downloaded from www.americandynamics.net http://www.americandynamics.net under Support/Software Downloads/Network Video Recorders.
Event History
Aug 3, 2023
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
RemedyDescriptionSeverityWeakness
Data Sourced
08:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-3749?
The severity of CVE-2023-3749 is high with a severity value of 5.5.
2
How does CVE-2023-3749 affect Johnsoncontrols Videoedge?
CVE-2023-3749 affects Johnsoncontrols Videoedge version up to 6.1.1.
3
What can a local user do if they exploit CVE-2023-3749?
A local user can edit the VideoEdge configuration file and interfere with VideoEdge operation.
4
How can I fix CVE-2023-3749?
To fix CVE-2023-3749, it is recommended to apply the necessary patches or updates provided by Johnsoncontrols.
5
Where can I find more information about CVE-2023-3749?
More information about CVE-2023-3749 can be found on the CISA and Johnsoncontrols websites.