{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-41920","assignerOrgId":"cf4a7ff5-dd38-4ede-a530-ffaa7ea59c39","state":"PUBLISHED","assignerShortName":"NCSC-NL","dateReserved":"2023-09-05T10:14:50.216Z","datePublished":"2024-07-02T07:42:24.484Z","dateUpdated":"2024-08-02T19:09:49.386Z"},"containers":{"cna":{"providerMetadata":{"orgId":"cf4a7ff5-dd38-4ede-a530-ffaa7ea59c39","shortName":"NCSC-NL","dateUpdated":"2024-07-02T08:20:30.865Z"},"title":"Authentication Bypass by Primary Weakness in Kiloview P1/P2 devices","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-305","description":"CWE-305 Authentication Bypass by Primary Weakness","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-115","descriptions":[{"lang":"en","value":"CAPEC-115 Authentication Bypass"}]}],"affected":[{"vendor":"Kiloview","product":"P1/P2","versions":[{"status":"affected","version":"All","lessThanOrEqual":"4.8.2605","versionType":"custom"}],"defaultStatus":"affected"}],"descriptions":[{"lang":"en","value":"The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, the root user is automatically logged in.","supportingMedia":[{"type":"text/html","base64":false,"value":"<span style=\"background-color: rgb(255, 255, 255);\">The vulnerability allows attackers access to the root account without having to authenticate. </span><span style=\"background-color: rgba(255, 255, 255, 0.7);\">Specifically, if the device is configured with the IP address of 10.10.10.10, the root user is automatically logged in.</span>\n\n"}]}],"references":[{"url":"https://advisories.ncsc.nl/advisory?id=NCSC-2024-0273"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"CRITICAL","baseScore":9.8,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}}],"source":{"discovery":"UNKNOWN"}},"adp":[{"affected":[{"vendor":"kiloview","product":"p1_4g_video_encoder_firmware","cpes":["cpe:2.3:o:kiloview:p1_4g_video_encoder_firmware:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThanOrEqual":"*","versionType":"custom"}]},{"vendor":"kiloview","product":"p2_4g_video_encoder_firmware","cpes":["cpe:2.3:o:kiloview:p2_4g_video_encoder_firmware:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThanOrEqual":"*","versionType":"custom"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-07-02T10:52:36.148784Z","id":"CVE-2023-41920","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-02T10:52:42.017Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T19:09:49.386Z"},"title":"CVE Program Container","references":[{"url":"https://advisories.ncsc.nl/advisory?id=NCSC-2024-0273","tags":["x_transferred"]}]}]}}