CVE-2013-1391

HIGHCVSS 7.5/10EPSS 76.11%

Last modified

CVE-2013-1391 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.. EPSS estimates a 76.11% chance of exploitation in the next 30 days.

Description

Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
76.11%

99.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuntcctvDvr-04ch FirmwareAll versions
HuntcctvDvr-04nc FirmwareAll versions
HuntcctvDvr-08ch FirmwareAll versions
HuntcctvDvr-08nc FirmwareAll versions
HuntcctvDvr-16ch FirmwareAll versions
HuntcctvDr6-704a4h FirmwareAll versions
HuntcctvDr6-708a4h FirmwareAll versions
HuntcctvDr6-7316a4h FirmwareAll versions
HuntcctvDr6-7316a4hl FirmwareAll versions
HuntcctvHdr-04kd FirmwareAll versions
HuntcctvHdr-08kd FirmwareAll versions
CapturecctvCdr 0410ve FirmwareAll versions
CapturecctvCdr 0820vde FirmwareAll versions
HachiHv-04rd Pro FirmwareAll versions
HachiHv-08rd Pro FirmwareAll versions
NovuscctvNv-Dvr1204 FirmwareAll versions
NovuscctvNv-Dvr1208 FirmwareAll versions
NovuscctvNv-Dvr1216 FirmwareAll versions
VspTw-Dvr604 FirmwareAll versions
VspTw-Dvr616 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-1391?
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.
How severe is CVE-2013-1391?
CVE-2013-1391 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 76.11% probability of exploitation in the next 30 days.
How do I fix CVE-2013-1391?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-1391?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST