MiniDVBLinux 5.4 Simple VideoDiskRecorder Protocol Remote Code Execution
Vulnerability Description
MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to send commands to manipulate TV systems. Attackers can send crafted SVDRP commands through the svdrpsend.sh script to execute messages and potentially control the video disk recorder remotely.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53774
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- LiquidWorm as Gjoko Krstic of Zero Science Lab
References
- https://www.exploit-db.com/exploits/51093
- https://www.linuxtv.org/vdrwiki/index.php/SVDRP#The_commands
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5714.php
- https://www.minidvblinux.de
- https://www.vulncheck.com/advisories/minidvblinux-simple-videodiskrecorder-protocol-remote-code-execution
More from MiniDVBLinux
View All →Affected Vendor
MiniDVBLinux
View all reports →