CVE-2024-41883
Severity CVSS v4.0:
MEDIUM
Type:
CWE-476
NULL Pointer Dereference
Publication date:
24/12/2024
Last modified:
24/12/2024
Description
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the <br />
<br />
NVR<br />
<br />
. An attacker enters a special value for a specific URL parameter, resulting in a NULL pointer reference and a reboot of the NVR. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer&#39;s report for details and workarounds.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM