Vulnerabilities > CVE-2024-3850 - Unspecified vulnerability in Uniview Nvr301-04S2-P4 Firmware

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
uniview

Summary

Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL that if clicked on could execute malicious JavaScript in their browser. This vulnerability also requires authentication before it can be exploited, so the scope and severity is limited. Also, even if JavaScript is executed, no additional benefits are obtained.

Vulnerable Configurations

Part Description Count
OS
Uniview
1
Hardware
Uniview
1