CVE-2023-4249

moderate-risk
Published 2023-11-08

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 has a command injection vulnerability in their implementation of their binaries and handling of network requests.

Do I need to act?

-
0.54% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10 High
NETWORK / LOW complexity

Affected Products (11)

Cf7500 Firmware
Cf7300 Firmware
Cf7201 Firmware
Cf7501 Firmware
Cb3211 Firmware
Cb3212 Firmware
Cb5220 Firmware
Cb6231 Firmware
B8520 Firmware
B8220 Firmware
Cd321 Firmware

Affected Vendors

48
/ 100
moderate-risk
Severity 30/34 · Critical
Exploitability 2/34 · Minimal
Exposure 16/34 · Moderate