CVE-2019-12223 - CVE House
Back to Database
Status published High CVE-2019-12223

An issue was discovered in NVR WebViewer on Hanwah Techwin...

Vulnerability Description

An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-12223

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

hanwha-security

View all reports →

Affected Software

srn-472s firmware, srn-873s firmware, srn-1673s firmware
Vulnerable Versions:
1.07_190502, 0

Timeline

Official Publish: September 5th, 2019
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.