Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-8655", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2024-09-10T13:11:16.184Z", "datePublished": "2024-09-10T19:31:04.014Z", "dateUpdated": "2024-09-12T13:43:51.121Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2024-09-10T19:31:04.014Z"}, "title": "Mercury MNVR816 web-static file access", "problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-552", "lang": "en", "description": "CWE-552 Files or Directories Accessible"}]}], "affected": [{"vendor": "Mercury", "product": "MNVR816", "versions": [{"version": "2.0.1.0.0", "status": "affected"}, {"version": "2.0.1.0.1", "status": "affected"}, {"version": "2.0.1.0.2", "status": "affected"}, {"version": "2.0.1.0.3", "status": "affected"}, {"version": "2.0.1.0.4", "status": "affected"}, {"version": "2.0.1.0.5", "status": "affected"}]}], "descriptions": [{"lang": "en", "value": "A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."}, {"lang": "de", "value": "Es wurde eine Schwachstelle in Mercury MNVR816 bis 2.0.1.0.5 ausgemacht. Sie wurde als problematisch eingestuft. Dabei betrifft es einen unbekannter Codeteil der Datei /web-static/. Mittels dem Manipulieren mit unbekannten Daten kann eine files or directories accessible-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."}], "metrics": [{"cvssV4_0": {"version": "4.0", "baseScore": 6.9, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N", "baseSeverity": "MEDIUM"}}, {"cvssV3_1": {"version": "3.1", "baseScore": 5.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseSeverity": "MEDIUM"}}, {"cvssV3_0": {"version": "3.0", "baseScore": 5.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseSeverity": "MEDIUM"}}, {"cvssV2_0": {"version": "2.0", "baseScore": 5, "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}}], "timeline": [{"time": "2024-09-10T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed"}, {"time": "2024-09-10T02:00:00.000Z", "lang": "en", "value": "VulDB entry created"}, {"time": "2024-09-10T15:16:22.000Z", "lang": "en", "value": "VulDB entry last update"}], "credits": [{"lang": "en", "value": "leetmoon (VulDB User)", "type": "reporter"}], "references": [{"url": "https://vuldb.com/?id.276963", "name": "VDB-276963 | Mercury MNVR816 web-static file access", "tags": ["vdb-entry"]}, {"url": "https://vuldb.com/?ctiid.276963", "name": "VDB-276963 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": ["signature", "permissions-required"]}, {"url": "https://vuldb.com/?submit.401301", "name": "Submit #401301 | Mercury MNVR816 Video Recorder 2.0.1.0.5 File and Directory Information Exposure", "tags": ["third-party-advisory"]}]}, "adp": [{"affected": [{"vendor": "mercurycom", "product": "mnvr816_firmware", "cpes": ["cpe:2.3:o:mercurycom:mnvr816_firmware:*:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "2.0.1.0.0", "status": "affected", "lessThanOrEqual": "2.0.1.0.5", "versionType": "custom"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-09-12T13:38:59.969361Z", "id": "CVE-2024-8655", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-12T13:43:51.121Z"}}]}}