Remote Code Execution Vulnerability in Hanwha Vision NVR Products
CVE-2024-41887
5.1MEDIUM
What is CVE-2024-41887?
A security flaw has been identified in Hanwha Vision's Network Video Recorder (NVR) systems that allows for remote code execution. An attacker can exploit this vulnerability by creating an NVR log file in a directory one level higher than intended, thereby corrupting files within the affected directory. This vulnerability potentially opens the door for unauthorized access and manipulation of critical system files. Hanwha Vision has actively responded to this issue by releasing a firmware patch to rectify the vulnerability. Users are advised to consult the manufacturer's report for detailed guidance on patching the affected systems and implementing necessary workarounds to mitigate risks.
Affected Version(s)
XRN-420S 5.01.62 and prior versions
