CVE-2017-7912
CRITICALHanwhasecurity Srn-4000 Firmware - Improper Access Control
Title source: ruleDescription
Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0065
EPSS Percentile
70.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-284
CWE-287
Status
published
Products (1)
hanwhasecurity/srn-4000_firmware
< 2.16_170401
Published
Apr 08, 2019
Tracked Since
Feb 18, 2026