SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-24-025-02 | Third Party Advisory US Government Resource | 
| https://www.cisa.gov/news-events/ics-advisories/icsa-24-025-02 | Third Party Advisory US Government Resource | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
Configuration 2 (hide)
| AND | 
 
 | 
Configuration 3 (hide)
| AND | 
 
 | 
History
                    21 Nov 2024, 08:45
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-025-02 - Third Party Advisory, US Government Resource | 
31 Jan 2024, 18:46
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-77 | |
| CPE | cpe:2.3:h:systemk-corp:nvr_508:-:*:*:*:*:*:*:* cpe:2.3:h:systemk-corp:nvr_516:-:*:*:*:*:*:*:* cpe:2.3:o:systemk-corp:nvr_516_firmware:2.3.5sk.30084998:*:*:*:*:*:*:* cpe:2.3:o:systemk-corp:nvr_504_firmware:2.3.5sk.30084998:*:*:*:*:*:*:* cpe:2.3:h:systemk-corp:nvr_504:-:*:*:*:*:*:*:* cpe:2.3:o:systemk-corp:nvr_508_firmware:2.3.5sk.30084998:*:*:*:*:*:*:* | |
| References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-025-02 - Third Party Advisory, US Government Resource | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.8 | 
25 Jan 2024, 19:28
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-01-25 19:15
Updated : 2024-11-21 08:45
NVD link : CVE-2023-7227
Mitre link : CVE-2023-7227
CVE.ORG link : CVE-2023-7227
JSON object : View
Products Affected
                systemk-corp
- nvr_516_firmware
- nvr_504_firmware
- nvr_516
- nvr_508
- nvr_508_firmware
- nvr_504
CWE
                
                    
                        
                        CWE-77
                        
            Improper Neutralization of Special Elements used in a Command ('Command Injection')
