NUUO Firmware Vulnerabilities Disclosed by Digital Defense, Inc. Researchers
Digital Defense, Inc., a security technology and services provider, announced that its Vulnerability Research Team (VRT) discovered a previously undisclosed vulnerability in NUUO NVRmini2 Network Video Recorder firmware. NVRmini2 firmware version 3.9.1 and prior is vulnerable to an unauthenticated remote buffer overflow that could potentially be leveraged by an attacker to execute arbitrary code on the system with root privileges. This could allow the attacker to access and/or modify the camera feeds to the NVR and change the configuration or recordings on the NVR.
Information regarding the security fixes can be obtained through NUUO.
Details of the individual vulnerabilities can be found on the Digital Defense blog.
Tom DeSot, EVP/Chief Information Officer at Digital Defense, said, "NUUO has worked closely with our VRT to ensure a fix is available to organizations utilizing the affected firmware. NUUO’s rapid response to the identification of the issue and collaboration has resulted in a quick resolution."
Digital Defense Research Methodology and Practices
The Digital Defense VRT regularly works with organizations in the responsible disclosure of zero-day vulnerabilities. The expertise of the VRT when coupled with the company’s next generation hybrid cloud platform, Frontline Vulnerability Manager, enables early detection capabilities. When zero-days are discovered and internally validated, the VRT immediately contacts the affected vendor to notify the organization of the new finding(s) and then assists, wherever possible, with the vendor’s remediation actions.
Date Posted: Tuesday, December 4, 2018
ContactCenterWorld.com is the world's premier on-line resource for the call and contact center industry. This article is one of hundreds available on-line to registered members. Our resource is updated every working day and includes content from every corner of the world. If you are not a registered member go to www.ContactCenterWorld.com and register today.