Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2021-44954
In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a Sudo misconfiguration.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.0
EPSS Ranking
11.8%
CVSS Severity
CVSS v3 Score
7.8
References
https://gist.github.com/Meeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee/a670418d51051d4e6513d86e84e8d5b8
https://twitter.com/Me9187/status/1414906288287404039
https://gist.github.com/Meeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee/a670418d51051d4e6513d86e84e8d5b8
https://twitter.com/Me9187/status/1414906288287404039
Products affected by CVE-2021-44954
Qvis
»
Dvr
»
Version:
N/A
cpe:2.3:h:qvis:dvr:-
Qvis
»
Nvr
»
Version:
N/A
cpe:2.3:h:qvis:nvr:-
Qvis
»
Dvr Firmware
»
Version:
Any
cpe:2.3:o:qvis:dvr_firmware:*
Qvis
»
Nvr Firmware
»
Version:
Any
cpe:2.3:o:qvis:nvr_firmware:*
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved