CVE-2017-14263

Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
honeywellenterprise_dvr_firmware
-
honeywellmaxpro_nvr_hybrid_se_firmware
-
honeywellmaxpro_nvr_hybrid_xe_firmware
-
honeywellmaxpro_nvr_se_firmware
-
honeywellmaxpro_nvr_xe_firmware
-
honeywellfusion_iv_rev_c_firmware
-
honeywellmaxpro_nvr_pe_firmware
-
𝑥
= Vulnerable software versions