CVE-2023-31996
HIGHCVSS 8.8/10EPSS 1.49%
Last modified
CVE-2023-31996 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special characters for the NAS storage test function.. EPSS estimates a 1.49% chance of exploitation in the next 30 days.
Description
Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special characters for the NAS storage test function.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hanwhavision | Ane-L6012r Firmware | < 1.41.03 |
| Hanwhavision | Ane-L7012r Firmware | < 1.41.03 |
| Hanwhavision | Ano-L6012r Firmware | < 1.41.03 |
| Hanwhavision | Ano-L6022r Firmware | < 1.41.03 |
| Hanwhavision | Ano-L6082r Firmware | < 1.41.03 |
| Hanwhavision | Ano-L7012r Firmware | < 1.41.03 |
| Hanwhavision | Ano-L7022r Firmware | < 1.41.03 |
| Hanwhavision | Ano-L7082r Firmware | < 1.41.03 |
| Hanwhavision | Anv-L6012r Firmware | < 1.41.03 |
| Hanwhavision | Anv-L6023r Firmware | < 1.41.03 |
| Hanwhavision | Anv-L6082r Firmware | < 1.41.03 |
| Hanwhavision | Anv-L7012r Firmware | < 1.41.03 |
| Hanwhavision | Anv-L7082r Firmware | < 1.41.03 |
| Hanwhavision | Pnm-12082rvd Firmware | < 2.22.00 |
| Hanwhavision | Pnm-7002vd Firmware | < 2.22.00 |
| Hanwhavision | Pnm-7082rvd Firmware | < 2.22.00 |
| Hanwhavision | Pnm-8082vt Firmware | < 2.22.00 |
| Hanwhavision | Pnm-9000qb Firmware | < 2.22.00 |
| Hanwhavision | Pnm-9000vd Firmware | < 2.22.00 |
| Hanwhavision | Pnm-9002vq Firmware | < 2.22.00 |
| Hanwhavision | Pnm-9022v Firmware | < 2.22.00 |
| Hanwhavision | Pnm-9031rv Firmware | < 2.22.00 |
| Hanwhavision | Pnm-9084qz1 Firmware | < 2.22.00 |
| Hanwhavision | Pnm-9084rqz Firmware | < 2.22.00 |
| Hanwhavision | Pnm-9084rqz1 Firmware | < 2.22.00 |
| Hanwhavision | Pnm-9085rqz Firmware | < 2.22.00 |
| Hanwhavision | Pnm-9085rqz1 Firmware | < 2.22.00 |
| Hanwhavision | Pnm-9322vqp Firmware | < 2.22.00 |
| Hanwhavision | Pnm-C12083rvd Firmware | < 2.22.00 |
| Hanwhavision | Pnm-C7083rvd Firmware | < 2.22.00 |
| Hanwhavision | Pnm-C9022rv Firmware | < 2.22.00 |
| Hanwhavision | Qnd-6011 Firmware | < 1.41.14 |
| Hanwhavision | Qnd-6012r Firmware | < 1.41.14 |
| Hanwhavision | Qnd-6012r1 Firmware | < 1.41.14 |
| Hanwhavision | Qnd-6021 Firmware | < 1.41.14 |
| Hanwhavision | Qnd-6022r Firmware | < 1.41.14 |
| Hanwhavision | Qnd-6082r Firmware | < 1.41.14 |
| Hanwhavision | Qnd-6082r1 Firmware | < 1.41.14 |
| Hanwhavision | Qnd-70142r Firmware | < 1.41.05 |
| Hanwhavision | Qnd-7022r Firmware | < 1.41.05 |
| Hanwhavision | Qnd-7032r Firmware | < 1.41.05 |
| Hanwhavision | Qnd-7082r Firmware | < 1.41.05 |
| Hanwhavision | Qnd-8010r Firmware | < 1.41.05 |
| Hanwhavision | Qnd-8011 Firmware | < 1.41.05 |
| Hanwhavision | Qnd-8020r Firmware | < 1.41.05 |
| Hanwhavision | Qnd-8021 Firmware | < 1.41.05 |
| Hanwhavision | Qnd-8080r Firmware | < 1.41.05 |
| Hanwhavision | Qne-8011r Firmware | < 1.41.05 |
| Hanwhavision | Qnf-8010 Firmware | < 1.41.05 |
| Hanwhavision | Qnf-9010 Firmware | < 1.41.05 |
Showing 50 of 118 affected configurations. See NVD for the full list.
References
- https://hanwhavisionamerica.com/download/50042/Vendor Advisory
- https://hanwhavisionamerica.com/download/50042/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-31996?
Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special characters for the NAS storage test function.
How severe is CVE-2023-31996?
CVE-2023-31996 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 1.49% probability of exploitation in the next 30 days.
How do I fix CVE-2023-31996?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2023-31996?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
