CVE-2023-5747
Last modified
CVE-2023-5747 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command injection allowing an attacker to run arbitrary code. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command injection allowing an attacker to run arbitrary code. HanwhaVision has released patched firmware for the highlighted flaw. Please refer to the hanwhavision security report for more information and solution."
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hanwhavision | Wave Server Software | < 5.1.1.37647 |
| Hanwhavision | Pno-A6081r-E1t Firmware | 2.21.02 |
| Hanwhavision | Pno-A6081r-E2t Firmware | 2.21.02 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5747?
How severe is CVE-2023-5747?
How do I fix CVE-2023-5747?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-5741The POWR plugin for WordPress is vulnerable to Stored Cross-…5.4
- CVE-2023-5742The EasyRotator for WordPress plugin for WordPress is vulner…5.4
- CVE-2023-5743The Telephone Number Linker plugin for WordPress is vulnerab…5.4
- CVE-2023-5744The Very Simple Google Maps plugin for WordPress is vulnerab…5.4
- CVE-2023-5745The Reusable Text Blocks plugin for WordPress is vulnerable …5.4
- CVE-2023-5746A vulnerability regarding use of externally-controlled forma…9.8
- CVE-2023-5748Buffer copy without checking size of input ('Classic Buffer …5.5
- CVE-2023-5749The EmbedPress WordPress plugin before 3.9.2 does not saniti…6.1
- CVE-2023-5750The EmbedPress WordPress plugin before 3.9.2 does not saniti…6.1
- CVE-2023-5751A local attacker with low privileges can read and modify any…7.8
- CVE-2023-5752When installing a package from a Mercurial VCS URL (ie "pip…3.3
- CVE-2023-5753Potential buffer overflows in the Bluetooth subsystem due to…8.8
Are you affected by CVE-2023-5747?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
