CVE-2013-7487

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
21/03/2020
Last modified:
25/03/2020

Description

On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to “system”, which allows remote attackers to execute arbitrary code via TCP port 9000.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:swann:dvr04b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:swann:dvr04b:-:*:*:*:*:*:*:*
cpe:2.3:o:swann:dvr08b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:swann:dvr08b:-:*:*:*:*:*:*:*
cpe:2.3:o:swann:dvr-16cif_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:swann:dvr-16cif:-:*:*:*:*:*:*:*
cpe:2.3:o:swann:dvr16b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:swann:dvr16b:-:*:*:*:*:*:*:*