CVE-2023-48121
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x build 20230401, Ezviz CS-C6CN-xxx prior to v5.3.x build 20230401, Ezviz CS-C3N-xxx prior to v5.3.x build 20230401 allows remote attackers to obtain sensitive information by sending crafted messages to the affected devices.
Una vulnerabilidad de omisión de autenticación en Direct Connection Module en Ezviz CS-C6N-xxx anterior a v5.3.x compilación 20230401, Ezviz CS-CV310-xxx anterior a v5.3.x compilación 20230401, Ezviz CS-C6CN-xxx anterior a v5.3.x compilación 20230401, Ezviz CS-C3N-xxx anterior a v5.3.x compilación 20230401 permite a atacantes remotos obtener información confidencial enviando mensajes manipulados a los dispositivos afectados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-11-13 CVE Reserved
- 2023-11-28 CVE Published
- 2024-08-02 CVE Updated
- 2024-12-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://joerngermany.github.io/ezviz_vulnerability | ||
https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.ezviz.com/data-security/security-notice/detail/911 | 2024-01-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ezviz Search vendor "Ezviz" | Cs-c6n-a0-1c2wfr Firmware Search vendor "Ezviz" for product "Cs-c6n-a0-1c2wfr Firmware" | - | - |
Affected
| in | Ezviz Search vendor "Ezviz" | Cs-c6n-a0-1c2wfr Search vendor "Ezviz" for product "Cs-c6n-a0-1c2wfr" | - | - |
Safe
|
Ezviz Search vendor "Ezviz" | Cs-cv310-a0-1c2wfr Firmware Search vendor "Ezviz" for product "Cs-cv310-a0-1c2wfr Firmware" | - | - |
Affected
| in | Ezviz Search vendor "Ezviz" | Cs-cv310-a0-1c2wfr Search vendor "Ezviz" for product "Cs-cv310-a0-1c2wfr" | - | - |
Safe
|
Ezviz Search vendor "Ezviz" | Cs-c6cn-a0-3h2wfr Firmware Search vendor "Ezviz" for product "Cs-c6cn-a0-3h2wfr Firmware" | - | - |
Affected
| in | Ezviz Search vendor "Ezviz" | Cs-c6cn-a0-3h2wfr Search vendor "Ezviz" for product "Cs-c6cn-a0-3h2wfr" | - | - |
Safe
|
Ezviz Search vendor "Ezviz" | Cs-c3n-a0-3h2wfrl Firmware Search vendor "Ezviz" for product "Cs-c3n-a0-3h2wfrl Firmware" | - | - |
Affected
| in | Ezviz Search vendor "Ezviz" | Cs-c3n-a0-3h2wfrl Search vendor "Ezviz" for product "Cs-c3n-a0-3h2wfrl" | - | - |
Safe
|