CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution
嗯,用户让我总结一篇文章,控制在一百个字以内,而且不需要用“文章内容总结”之类的开头。我得先仔细阅读文章内容,抓住关键点。 文章讲的是美国网络安全和基础设施安全局(CISA)将一个影响Digiever DS-2105 Pro网络视频录像机的漏洞加入到已知被利用的漏洞目录中。这个漏洞CVE-2023-52163,CVSS评分8.8,属于命令注入漏洞,允许经过身份验证的远程代码执行。 接着,文章提到这个漏洞被加入目录是因为有多个报告指出威胁行为者利用它传播恶意软件如Mirai和ShadowV2。设备已经到了生命周期末期,所以没有补丁。成功利用需要攻击者登录设备并发送特定请求。建议用户避免将设备暴露在互联网上,并更改默认凭据。CISA还要求联邦机构在2025年1月前应用缓解措施或停止使用该产品。 现在我要把这些信息浓缩到一百字以内。要包括CISA、漏洞名称、影响、CVSS评分、攻击方式、设备EoL、建议措施和截止日期。 可能的结构:CISA将CVE-2023-52163漏洞加入目录,影响Digiever NVRs,CVSS 8.8,允许远程代码执行。由于设备已到生命周期末期,无补丁。建议更改凭据并避免暴露设备。FCEB机构需在2025年1月前采取措施。 检查字数是否在限制内,并确保信息准确全面。 </think> CISA将影响Digiever DS-2105 Pro网络视频录像机的CVE-2023-52163漏洞加入已知被利用的漏洞目录,该漏洞CVSS评分为8.8,允许经过身份验证的远程代码执行。由于设备已到生命周期末期且无补丁可用,建议用户避免暴露设备并更改默认凭据。CISA要求联邦机构于2025年1月前采取缓解措施或停止使用该产品以应对活跃威胁。 2025-12-25 08:7:0 Author: thehackernews.com(查看原文) 阅读量:5 收藏

Vulnerability / Endpoint Security

Digiever NVR Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw impacting Digiever DS-2105 Pro network video recorders (NVRs) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2023-52163 (CVSS score: 8.8), relates to a case of command injection that allows post-authentication remote code execution.

"Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi," CISA said.

Cybersecurity

The addition of CVE-2023-52163 to the KEV catalog comes in the multiple reports from Akamai and Fortinet about the exploitation of the flaw by threat actors to deliver botnets like Mirai and ShadowV2.

According to TXOne Research security researcher Ta-Lun Yen, the vulnerability, alongside an arbitrary file read bug (CVE-2023-52164, CVSS score: 5.1), remains unpatched due to the device reaching end-of-life (EoL) status.

Successful exploitation requires an attacker to be logged into the device and perform a crafted request. In the absence of a patch, it's advised that users avoid exposing the device to the internet and change the default username and password.

CISA is also recommending that Federal Civilian Executive Branch (FCEB) agencies apply the necessary mitigations or discontinue use of the product by January 12, 2025, to secure their network from active threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2025/12/cisa-flags-actively-exploited-digiever.html
如有侵权请联系:admin#unsafe.sh