CameraRisk

CVE-2023-38585

CBC / Ganz

Published
23 August 2023
Last modified
17 June 2026
CVSS
8.8 v3.1
Severity
high
EPSS
1.1% (63th pct)
CISA KEV
Not listed
NVD status
Modified
Weaknesses
CWE-287

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates for those products are not provided.

Exploitation

Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 1.1% probability of exploitation activity in the next 30 days.

Affected products

ProductVendorTypeVersions named
DR-16F42A CBC / Ganz unknown
DR-16F45AT CBC / Ganz unknown
DR-16H CBC / Ganz unknown
DR-16M52 CBC / Ganz unknown
DR-16M52-AV CBC / Ganz unknown
DR-4FX1 CBC / Ganz unknown
DR-4H CBC / Ganz unknown
DR-4M51-AV CBC / Ganz unknown
DR-8F42A CBC / Ganz unknown
DR-8F45AT CBC / Ganz unknown
DR-8H CBC / Ganz unknown
DR-8M52-AV CBC / Ganz unknown
DRH8-4M41-A CBC / Ganz unknown
NR-16F82-16P CBC / Ganz unknown
NR-16F85-8PRA CBC / Ganz unknown
NR-16M CBC / Ganz unknown
NR-4F CBC / Ganz unknown
NR-8F CBC / Ganz unknown
NR16H CBC / Ganz unknown
NR4H CBC / Ganz unknown
NR8-4M71 CBC / Ganz unknown
NR8-8M72 CBC / Ganz unknown
NR8H CBC / Ganz unknown

References

Vendor advisory and patch

CVE-2023-38585 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.