PT-2026-97113 · Openeye · Apex Network Video Recorder
CVSS v3.1
6.2
Medium
| Vector | AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenEye Apex Network Video Recorder (NVR) versions 2.2.3.4 through 3.2.9.376
Description
The administrator password-reset unlock-code design lacks a per-device secret or server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code offline to reset the administrator password.
Recommendations
Upgrade to version 3.5.4.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apex Network Video Recorder