CVE-2021-41419
Summary
| CVE | CVE-2021-41419 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-18 00:15:00 UTC |
| Updated | 2022-07-25 19:58:00 UTC |
| Description | QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qvis | Dvr | - | All | All | All |
| Operating System | Qvis | Dvr Firmware | All | All | All | All |
| Hardware | Qvis | Nvr | - | All | All | All |
| Operating System | Qvis | Nvr Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Me on Twitter: "For more detail, This is an unauthenticated RCE in QVIS DVRs via java deserialization, Multiple disclosure attempts were made to QVIS by me and 3rd parties over the past year which were actively ignored. use this template with @pdnuclei https://t.co/CdgpmWwnii… https://t.co/95tihMBIm4" | MISC | twitter.com | |
| CVE-2021-41419 · GitHub | MISC | gist.github.com | |
| nuclei-templates/qvisdvr-deserialization-rce.yaml at master · projectdiscovery/nuclei-templates · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.