U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-0778

Change History

New CVE Received by NIST 1/22/2024 11:15:08 AM

Action Type Old Value New Value
Added CVSS V2

								
							
							
						
VulDB (AV:A/AC:L/Au:S/C:C/I:C/A:C)
Added CVSS V3.1

								
							
							
						
VulDB AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
VulDB CWE-78
Added Description

								
							
							
						
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930. Affected by this issue is the function setNatConfig of the file /Interface/DevManage/VM.php. The manipulation of the argument natAddress/natPort/natServerPort leads to os command injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251696. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
Added Reference

								
							
							
						
VulDB https://github.com/dezhoutorizhao/cve/blob/main/rce.md [No types assigned]
Added Reference

								
							
							
						
VulDB https://vuldb.com/?ctiid.251696 [No types assigned]
Added Reference

								
							
							
						
VulDB https://vuldb.com/?id.251696 [No types assigned]