← Back to CVE List

CVE-2017-14263

Published: 2017-09-11T09:29Z
Last Modified: 2024-11-21T03:12Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt