On Samsung NVR devices, remote attackers can read the MD5 password hash of the admin account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Srn_1670d_firmware | Samsung | - (including) | - (including) |