CVE-2023-3704
Timestamp Modification Vulnerability in CP-Plus Digital Video Recorder
Severity Score
5.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.
Successful exploitation of this vulnerability could allow the remote attacker to change system time of the targeted device.
*Credits:
This vulnerability is reported by Souvik Kandar and Arko Dhar from Redinent Innovations Engineering & Research Team, Karnataka, India.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-07-17 CVE Reserved
- 2023-08-24 CVE Published
- 2024-08-30 EPSS Updated
- 2024-10-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0240 | 2023-09-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-1601e1-hc Firmware Search vendor "Cpplusworld" for product "Cp-uvr-1601e1-hc Firmware" | < 4.000.00at008.0.0.r20230302 Search vendor "Cpplusworld" for product "Cp-uvr-1601e1-hc Firmware" and version " < 4.000.00at008.0.0.r20230302" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-1601e1-hc Search vendor "Cpplusworld" for product "Cp-uvr-1601e1-hc" | - | - |
Safe
|
Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0401l1-4kh Firmware Search vendor "Cpplusworld" for product "Cp-uvr-0401l1-4kh Firmware" | < 4.000.00at008.0.0.r20230302 Search vendor "Cpplusworld" for product "Cp-uvr-0401l1-4kh Firmware" and version " < 4.000.00at008.0.0.r20230302" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0401l1-4kh Search vendor "Cpplusworld" for product "Cp-uvr-0401l1-4kh" | - | - |
Safe
|
Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0401l1b-4kh Firmware Search vendor "Cpplusworld" for product "Cp-uvr-0401l1b-4kh Firmware" | < 4.000.00at008.0.0.r20230302 Search vendor "Cpplusworld" for product "Cp-uvr-0401l1b-4kh Firmware" and version " < 4.000.00at008.0.0.r20230302" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0401l1b-4kh Search vendor "Cpplusworld" for product "Cp-uvr-0401l1b-4kh" | - | - |
Safe
|
Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0801f1-hc Firmware Search vendor "Cpplusworld" for product "Cp-uvr-0801f1-hc Firmware" | < 4.000.00at008.0.0.r20230302 Search vendor "Cpplusworld" for product "Cp-uvr-0801f1-hc Firmware" and version " < 4.000.00at008.0.0.r20230302" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0801f1-hc Search vendor "Cpplusworld" for product "Cp-uvr-0801f1-hc" | - | - |
Safe
|
Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0801k1-h Firmware Search vendor "Cpplusworld" for product "Cp-uvr-0801k1-h Firmware" | < 4.000.00at008.0.0.r20230302 Search vendor "Cpplusworld" for product "Cp-uvr-0801k1-h Firmware" and version " < 4.000.00at008.0.0.r20230302" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0801k1-h Search vendor "Cpplusworld" for product "Cp-uvr-0801k1-h" | - | - |
Safe
|
Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0801k1b-h Firmware Search vendor "Cpplusworld" for product "Cp-uvr-0801k1b-h Firmware" | < 4.000.00at008.0.0.r20230302 Search vendor "Cpplusworld" for product "Cp-uvr-0801k1b-h Firmware" and version " < 4.000.00at008.0.0.r20230302" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0801k1b-h Search vendor "Cpplusworld" for product "Cp-uvr-0801k1b-h" | - | - |
Safe
|
Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0808k1-h Firmware Search vendor "Cpplusworld" for product "Cp-uvr-0808k1-h Firmware" | < 4.000.00at008.0.0.r20230302 Search vendor "Cpplusworld" for product "Cp-uvr-0808k1-h Firmware" and version " < 4.000.00at008.0.0.r20230302" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-0808k1-h Search vendor "Cpplusworld" for product "Cp-uvr-0808k1-h" | - | - |
Safe
|
Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-1601e1-h Firmware Search vendor "Cpplusworld" for product "Cp-uvr-1601e1-h Firmware" | < 4.000.00at008.0.0.r20230302 Search vendor "Cpplusworld" for product "Cp-uvr-1601e1-h Firmware" and version " < 4.000.00at008.0.0.r20230302" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-1601e1-h Search vendor "Cpplusworld" for product "Cp-uvr-1601e1-h" | - | - |
Safe
|
Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-1601e2-h Firmware Search vendor "Cpplusworld" for product "Cp-uvr-1601e2-h Firmware" | < 4.000.00at008.0.0.r20230302 Search vendor "Cpplusworld" for product "Cp-uvr-1601e2-h Firmware" and version " < 4.000.00at008.0.0.r20230302" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-uvr-1601e2-h Search vendor "Cpplusworld" for product "Cp-uvr-1601e2-h" | - | - |
Safe
|