Vulnerabilities > CVE-2021-41419 - Deserialization of Untrusted Data vulnerability in Qvis DVR Firmware and NVR Firmware

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
qvis
CWE-502
critical

Summary

QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.

Vulnerable Configurations

Part Description Count
OS
Qvis
2
Hardware
Qvis
2

Common Weakness Enumeration (CWE)