CVE-2023-5747: Command injection via wave install file
Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command injection allowing an attacker to run arbitrary code. HanwhaVision has released patched firmware for the highlighted flaw. Please refer to the hanwhavision security report for more information and solution."
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5747?
CVE-2023-5747 is a vulnerability that allows for command injection during the installation of HanwhaVision Wave server software.
What is the severity of CVE-2023-5747?
The severity of CVE-2023-5747 is high (8.8).
Which software versions are affected by CVE-2023-5747?
HanwhaVision Wave server software versions up to and including 5.1.1.37647 and HanwhaVision Pno-a6081r-e1t Firmware version 2.21.02 are affected.
How can an attacker exploit CVE-2023-5747?
An attacker can exploit CVE-2023-5747 by injecting arbitrary commands during the installation of Wave on the camera device, allowing them to run remote code.
Is HanwhaVision Pno-a6081r-e1t vulnerable to CVE-2023-5747?
No, HanwhaVision Pno-a6081r-e1t is not vulnerable to CVE-2023-5747.