Lucene search

K
cve[email protected]CVE-2022-47618
HistoryJan 03, 2023 - 3:15 a.m.

CVE-2022-47618

2023-01-0303:15:10
CWE-798
web.nvd.nist.gov
28
cve-2022-47618
merit lilin
ah55b04
ah55b08
dvr
hard-coded credentials
administrator
remote attacker
system manipulation

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.8%

Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service.

Affected configurations

NVD
Node
meritlilinah55b08Match-
AND
meritlilinah55b08_firmwareMatch-
Node
meritlilinah55b04Match-
AND
meritlilinah55b04_firmwareMatch-

CNA Affected

[
  {
    "vendor": "Merit Lilin Ent. Co., Ltd.",
    "product": "AH55B04 DVR firmware",
    "versions": [
      {
        "version": "unspecified",
        "lessThanOrEqual": "SVN#7570",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Merit Lilin Ent. Co., Ltd.",
    "product": "AH55B08 DVR firmware",
    "versions": [
      {
        "version": "unspecified",
        "lessThanOrEqual": "SVN#7570",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.8%

Related for CVE-2022-47618