Uniview IP Cameras Improper Authentication (CVE-2023-0773)

critical Tenable OT Security Plugin ID 506029

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Some Uniview IPC products have an access control vulnerability in their web-based management interface. A remote, unauthenticated attacker can send specially crafted HTTP requests to modify device user credentials.

Successful exploitation of this vulnerability could allow the attacker to gain complete control of the targeted device.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Upgrade the device to the fixed firmware build for its release branch, as listed in Uniview security notice USRC-202309-01:

- CIPC-B2303.3.3.230322 or later
- DIPC-B1213.7.2.230315 or later
- DIPC-B1216.6.2.230315 or later
- DIPC-B1219.2.71.230221 or later
- DIPC-B1221.5.2.230315 or later
- DIPC-B1222.5.2.230309 or later
- DIPC-B1223.5.3.230324 or later
- DIPC-B1225.5.2.230315 or later
- DIPC-B1226.5.2.230315 or later
- DIPC-B1228.5.3.230324 or later
- DIPC-B1229.1.69.230515 or later

See Also

http://www.nessus.org/u?665f6a51

http://www.nessus.org/u?b610b7cd

Plugin Details

Severity: Critical

ID: 506029

File Name: tenable_ot_uniview_CVE-2023-0773.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.12

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:uniview:ipc322lb-sf28-a_firmware

Required KB Items: Tenable.ot/Uniview

Patch Publication Date: 9/11/2023

Vulnerability Publication Date: 9/11/2023

Reference Information

CVE: CVE-2023-0773

CWE: 287