Remote Code Execution Vulnerability in Hanwha Vision NVR Products
CVE-2024-41887

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 December 2024

What is CVE-2024-41887?

A security flaw has been identified in Hanwha Vision's Network Video Recorder (NVR) systems that allows for remote code execution. An attacker can exploit this vulnerability by creating an NVR log file in a directory one level higher than intended, thereby corrupting files within the affected directory. This vulnerability potentially opens the door for unauthorized access and manipulation of critical system files. Hanwha Vision has actively responded to this issue by releasing a firmware patch to rectify the vulnerability. Users are advised to consult the manufacturer's report for detailed guidance on patching the affected systems and implementing necessary workarounds to mitigate risks.

Affected Version(s)

XRN-420S 5.01.62 and prior versions

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-41887 : Remote Code Execution Vulnerability in Hanwha Vision NVR Products