An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x build 20230401, Ezviz CS-C6CN-xxx prior to v5.3.x build 20230401, Ezviz CS-C3N-xxx prior to v5.3.x build 20230401 allows remote attackers to obtain sensitive information by sending crafted messages to the affected devices.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
No history.
Information
Published : 2023-11-28 19:15
Updated : 2024-01-09 14:15
NVD link : CVE-2023-48121
Mitre link : CVE-2023-48121
CVE.ORG link : CVE-2023-48121
JSON object : View
Products Affected
ezviz
- cs-c6cn-a0-3h2wfr_firmware
- cs-cv310-a0-1c2wfr_firmware
- cs-c3n-a0-3h2wfrl_firmware
- cs-c3n-a0-3h2wfrl
- cs-c6n-a0-1c2wfr
- cs-c6n-a0-1c2wfr_firmware
- cs-cv310-a0-1c2wfr
- cs-c6cn-a0-3h2wfr
CWE
CWE-287
Improper Authentication