CVE-2017-14262
Severity CVSS v4.0:
Pending analysis
Type:
CWE-326
Inadequate Encryption Strength
Publication date:
11/09/2017
Last modified:
20/04/2025
Description
On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:samsung:srn_1670d_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:samsung:srn_1670d:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:samsung:srn_1000_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:samsung:srn_1000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:samsung:srn_472s_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:samsung:srn_472s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:samsung:srn_470d_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:samsung:srn_470d:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



