What the vulnerability does

01Description

Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.

Key dates

02Disclosure timeline

April 8, 2019 CVE published
August 5, 2024 Record updated