CVE-2023-5037 is an authenticated command injection vulnerability affecting Hanwha Vision cameras, discovered by security researcher "badmonkey." An attacker with high privileges can inject malicious commands into request packets, leading to high impact on confidentiality, integrity, and availability. The vulnerability has a CVSS score of 7.2 (HIGH) but is not currently listed on CISA's KEV catalog, nor is there public exploit code or significant community discussion. The manufacturer has released patch firmware to address this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.41.16CPE matchmatch criteria | cpe:2.3:o:hanwhavision:ano-l6012r_firmware:*:*:*:*:*:*:*:* | ||
< 1.41.16CPE matchmatch criteria | cpe:2.3:o:hanwhavision:ano-l6022r_firmware:*:*:*:*:*:*:*:* | ||
< 1.41.16CPE matchmatch criteria | cpe:2.3:o:hanwhavision:anv-l6012r_firmware:*:*:*:*:*:*:*:* | ||
< 1.41.16CPE matchmatch criteria | cpe:2.3:o:hanwhavision:ano-l6082r_firmware:*:*:*:*:*:*:*:* | ||
< 1.41.16CPE matchmatch criteria | cpe:2.3:o:hanwhavision:ane-l6012r_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.