CVE-2023-3705
Information Disclosure Vulnerability in CP-Plus Network Video Recorder
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.
Successful exploitation of this vulnerability could allow the remote attacker to obtain sensitive information on the targeted device.
*Credits:
This vulnerability is reported by Souvik Kandar and Arko Dhar from Redinent Innovations Engineering & Research Team, Karnataka, India.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-07-17 CVE Reserved
- 2023-08-24 CVE Published
- 2024-10-02 CVE Updated
- 2024-10-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0239 | 2023-08-31 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cpplusworld Search vendor "Cpplusworld" | Cp-vnr-3104 Firmware Search vendor "Cpplusworld" for product "Cp-vnr-3104 Firmware" | < b3223p22c02424 Search vendor "Cpplusworld" for product "Cp-vnr-3104 Firmware" and version " < b3223p22c02424" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-vnr-3104 Search vendor "Cpplusworld" for product "Cp-vnr-3104" | - | - |
Safe
|
Cpplusworld Search vendor "Cpplusworld" | Cp-vnr-3108 Firmware Search vendor "Cpplusworld" for product "Cp-vnr-3108 Firmware" | < b3223p22c02424 Search vendor "Cpplusworld" for product "Cp-vnr-3108 Firmware" and version " < b3223p22c02424" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-vnr-3108 Search vendor "Cpplusworld" for product "Cp-vnr-3108" | - | - |
Safe
|
Cpplusworld Search vendor "Cpplusworld" | Cp-vnr-3208 Firmware Search vendor "Cpplusworld" for product "Cp-vnr-3208 Firmware" | < b3223p22c02424 Search vendor "Cpplusworld" for product "Cp-vnr-3208 Firmware" and version " < b3223p22c02424" | - |
Affected
| in | Cpplusworld Search vendor "Cpplusworld" | Cp-vnr-3208 Search vendor "Cpplusworld" for product "Cp-vnr-3208" | - | - |
Safe
|