CVE-2018-11689

MEDIUMCVSS 6.1/10EPSS 1.57%

Last modified

CVE-2018-11689 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.). EPSS estimates a 1.57% chance of exploitation in the next 30 days.

Description

Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)

Metrics

CVSS 3.1
6.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Probability
1.57%

72.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SamsungSmartviewerAll versions
Hanwha-SecurityHrd-1642 Firmware<= 1.16
Hanwha-SecurityHrd-842 Firmware<= 1.16
Hanwha-SecurityHrd-442 Firmware<= 1.16
Hanwha-SecurityHrd-1641 Firmware<= 1.14
Hanwha-SecurityHrd-841 Firmware<= 1.14
Hanwha-SecurityHrd-840 Firmware<= 1.14
Hanwha-SecurityHrd-440 Firmware<= 1.14
Hanwha-SecurityHrd-443 Firmware<= 1.14
Hanwha-SecuritySrd-1694u Firmware<= 1.14

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-11689?
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
How severe is CVE-2018-11689?
CVE-2018-11689 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 1.57% probability of exploitation in the next 30 days.
How do I fix CVE-2018-11689?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-11689?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST