Security Advisory

CVE-2017-14262

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-09-11 09:00:00
Last updated 2024-08-05 19:20:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.