CVE-2018-11689
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
14/06/2018
Last modified:
24/04/2022
Description
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:samsung:smartviewer:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwha-security:hrd-1642_firmware:*:*:*:*:*:*:*:* | 1.16 (including) | |
| cpe:2.3:h:hanwha-security:hrd-1642:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwha-security:hrd-842_firmware:*:*:*:*:*:*:*:* | 1.16 (including) | |
| cpe:2.3:h:hanwha-security:hrd-842:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwha-security:hrd-442_firmware:*:*:*:*:*:*:*:* | 1.16 (including) | |
| cpe:2.3:h:hanwha-security:hrd-442:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwha-security:hrd-1641_firmware:*:*:*:*:*:*:*:* | 1.14 (including) | |
| cpe:2.3:h:hanwha-security:hrd-1641:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwha-security:hrd-841_firmware:*:*:*:*:*:*:*:* | 1.14 (including) | |
| cpe:2.3:h:hanwha-security:hrd-841:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwha-security:hrd-840_firmware:*:*:*:*:*:*:*:* | 1.14 (including) | |
| cpe:2.3:h:hanwha-security:hrd-840:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hanwha-security:hrd-440_firmware:*:*:*:*:*:*:*:* | 1.14 (including) | |
| cpe:2.3:h:hanwha-security:hrd-440:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



