ID:1379 - Exploit for Information disclosure in Ds-2cd7153-e and Hikvision DVR/NVR Firmware - CVE-2013-4975

 
Main Vulnerability Database Exploits ID:1379 - Exploit for Information disclosure in Ds-2cd7153-e and Hikvision DVR/NVR Firmware - CVE-2013-4975

ID:1379 - Exploit for Information disclosure in Ds-2cd7153-e and Hikvision DVR/NVR Firmware - CVE-2013-4975

Published: March 18, 2020


Vulnerability identifier: #VU9531
Vulnerability risk: Low
CVE-ID: CVE-2013-4975
CWE-ID: CWE-200
Exploitation vector: Remote access
Vulnerable software:
Ds-2cd7153-e
Hikvision DVR/NVR Firmware

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to unknown error when handling malicious input. A remote attacker can send specially crafted data and obtain the admin password from a non-privileged user account.

Remediation

Update to the latest firmware version.