Vulnerabilities > CVE-2021-44954 - Unspecified vulnerability in Qvis DVR Firmware and NVR Firmware

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
qvis

Summary

In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a Sudo misconfiguration.

Vulnerable Configurations

Part Description Count
OS
Qvis
2
Hardware
Qvis
2