CVE-2023-47213

First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB, MD-404AB, and MD-808AB. As for the other products, apply the workaround.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:c-first:cfr-1004ea_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-1004ea:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:c-first:cfr-1008ea_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-1008ea:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:c-first:cfr-1016ea_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-1016ea:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:c-first:cfr-16eaa_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-16eaa:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:c-first:cfr-16eab_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-16eab:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:c-first:cfr-16eha_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-16eha:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:c-first:cfr-16ehd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-16ehd:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:c-first:cfr-4eaa_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-4eaa:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:c-first:cfr-4eaam_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-4eaam:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:c-first:cfr-4eab_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-4eab:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:c-first:cfr-4eabc_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-4eabc:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:c-first:cfr-4eha_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-4eha:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:c-first:cfr-4ehd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-4ehd:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:c-first:cfr-8eaa_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-8eaa:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:c-first:cfr-8eab_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-8eab:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:c-first:cfr-8eha_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-8eha:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:c-first:cfr-8ehd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-8ehd:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:c-first:cfr-904e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-904e:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:c-first:cfr-908e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-908e:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:c-first:cfr-916e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:cfr-916e:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:c-first:md-404aa_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:md-404aa:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:c-first:md-404ab_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:md-404ab:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:c-first:md-404ha_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:md-404ha:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:c-first:md-404hd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:md-404hd:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:c-first:md-808aa_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:md-808aa:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:c-first:md-808ab_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:md-808ab:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:c-first:md-808ha_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:md-808ha:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:c-first:md-808hd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:c-first:md-808hd:-:*:*:*:*:*:*:*

History

05 Dec 2023, 19:13

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-16 08:15

Updated : 2024-02-05 00:22


NVD link : CVE-2023-47213

Mitre link : CVE-2023-47213

CVE.ORG link : CVE-2023-47213


JSON object : View

Products Affected

c-first

  • md-404hd_firmware
  • cfr-1004ea_firmware
  • md-808hd_firmware
  • cfr-4eha_firmware
  • md-808aa
  • cfr-8eaa
  • md-404aa
  • cfr-4eaam_firmware
  • md-808aa_firmware
  • md-808ab
  • md-404ab_firmware
  • cfr-8eha_firmware
  • cfr-1008ea
  • cfr-4eaa
  • md-808ha_firmware
  • cfr-4eha
  • cfr-8eaa_firmware
  • cfr-4eab_firmware
  • cfr-4eaa_firmware
  • cfr-904e_firmware
  • md-404hd
  • cfr-16ehd_firmware
  • md-808ha
  • cfr-908e
  • cfr-4eabc_firmware
  • cfr-4ehd
  • cfr-4ehd_firmware
  • cfr-16eaa_firmware
  • cfr-916e_firmware
  • cfr-16ehd
  • cfr-16eab_firmware
  • cfr-908e_firmware
  • cfr-904e
  • cfr-1004ea
  • cfr-4eaam
  • cfr-8eab
  • cfr-8ehd_firmware
  • cfr-1008ea_firmware
  • md-404ab
  • cfr-16eaa
  • cfr-8eha
  • md-404aa_firmware
  • md-404ha_firmware
  • cfr-16eab
  • cfr-8ehd
  • cfr-16eha_firmware
  • cfr-16eha
  • cfr-4eab
  • md-404ha
  • cfr-1016ea
  • md-808ab_firmware
  • cfr-4eabc
  • cfr-8eab_firmware
  • md-808hd
  • cfr-916e
  • cfr-1016ea_firmware
CWE
CWE-798

Use of Hard-coded Credentials