CVE-2017-14263
HIGH 9.3EPSS 3.7%
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.
- CVSS v3.0
- 8.1 HIGH
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 3.74% chance of exploitation in the next 30 days, 89th percentile
- Published
- 2017-09-11
- Updated
- 2024-08-05
Proof-of-concept exploits (1)
- zzz66686/CVE-2017-142635★ · 2017-09-13