hanwha-security 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
一般的な弱点パターンには vendor risk cross-site scripting、vendor risk csrf、パス処理の欠陥, and vendor risk input validation があり、vendor surface production workloads の利用場面で vendor impact unexpected behavior、ファイル上書き, and vendor impact session compromise などのリスクが生じる可能性があります。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2019-12223 | An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device. | [email protected] | 7.5 | 0.48% | 2019-09-05 | 2024-11-21 |
| CVE-2018-11689 | Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.) | [email protected] | 6.1 | 0.56% | 2018-06-14 | 2024-11-21 |
| CVE-2018-6303 | Denial of service by uploading malformed firmware in Hanwha Techwin Smartcams | [email protected] | 7.5 | 0.41% | 2018-03-13 | 2024-11-21 |
| CVE-2018-6302 | Denial of service by blocking of new camera registration on the cloud server in Hanwha Techwin Smartcams | [email protected] | 7.5 | 0.41% | 2018-03-13 | 2024-11-21 |
| CVE-2018-6301 | Arbitrary camera access and monitoring via cloud in Hanwha Techwin Smartcams | [email protected] | 7.5 | 0.39% | 2018-03-13 | 2024-11-21 |
| CVE-2018-6300 | Remote password change in Hanwha Techwin Smartcams | [email protected] | 9.8 | 0.43% | 2018-03-13 | 2024-11-21 |
| CVE-2018-6299 | Authentication bypass in Hanwha Techwin Smartcams | [email protected] | 9.8 | 0.53% | 2018-03-13 | 2024-11-21 |
| CVE-2018-6298 | Remote code execution in Hanwha Techwin Smartcams | [email protected] | 9.8 | 3.22% | 2018-03-13 | 2024-11-21 |
| CVE-2018-6297 | Buffer overflow in Hanwha Techwin Smartcams | [email protected] | 9.8 | 0.54% | 2018-03-13 | 2024-11-21 |
| CVE-2018-6296 | An undocumented (hidden) capability for switching the web interface in Hanwha Techwin Smartcams | [email protected] | 5.3 | 0.29% | 2018-03-13 | 2024-11-21 |
| CVE-2018-6295 | Unencrypted way of remote control and communications in Hanwha Techwin Smartcams | [email protected] | 9.8 | 0.24% | 2018-03-13 | 2024-11-21 |
| CVE-2018-6294 | Unsecured way of firmware update in Hanwha Techwin Smartcams | [email protected] | 9.8 | 0.43% | 2018-03-13 | 2024-11-21 |
| CVE-2017-5169 | An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior. Multiple Cross Site Request Forgery vulnerabilities have been identified. The flaws exist within the Redis and Apache Felix Gogo servers that are installed as part of this product. By issuing specific HTTP Post requests, an attacker can gain system level access to a remote shell session. Smart Security Manager Versions 1.5 and prior are affected by these vulnerabilities. These vulnerabilities can allow for r | [email protected] | 7.5 | 0.30% | 2017-02-13 | 2026-05-13 |
| CVE-2017-5168 | An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior. Multiple Path Traversal vulnerabilities have been identified. The flaws exist within the ActiveMQ Broker service that is installed as part of the product. By issuing specific HTTP requests, if a user visits a malicious page, an attacker can gain access to arbitrary files on the server. Smart Security Manager Versions 1.4 and prior to 1.31 are affected by these vulnerabilities. These vulnerabilities can allow | [email protected] | 7.5 | 4.32% | 2017-02-13 | 2026-05-13 |