CVE-2024-47001
Status: DeferredHigh (8.8)—
Hidden functionality issue in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 8.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.66%
- Percentile among all scored CVEs: 50
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-912
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-47001",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-47001",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-09-18T14:58:04.072398Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "TAKENAKA ENGINEERING CO., LTD.",
"product": "HDVR-400",
"versions": [
{
"status": "affected",
"version": "prior to 46110.1.100869.65"
}
]
},
{
"vendor": "TAKENAKA ENGINEERING CO., LTD.",
"product": "HDVR-800",
"versions": [
{
"status": "affected",
"version": "prior to 53210.1.900103.65"
}
]
},
{
"vendor": "TAKENAKA ENGINEERING CO., LTD.",
"product": "HDVR-1600",
"versions": [
{
"status": "affected",
"version": "prior to 53310.1.900111.65"
}
]
},
{
"vendor": "TAKENAKA ENGINEERING CO., LTD.",
"product": "AHD04T-A",
"versions": [
{
"status": "affected",
"version": "prior to 7xx10.1.900055.65"
}
]
},
{
"vendor": "TAKENAKA ENGINEERING CO., LTD.",
"product": "AHD08T-A",
"versions": [
{
"status": "affected",
"version": "prior to 7xx10.1.900055.65"
}
]
},
{
"vendor": "TAKENAKA ENGINEERING CO., LTD.",
"product": "AHD16T-A",
"versions": [
{
"status": "affected",
"version": "prior to 7xx10.1.900055.65"
}
]
},
{
"vendor": "TAKENAKA ENGINEERING CO., LTD.",
"product": "NVR04T-A",
"versions": [
{
"status": "affected",
"version": "prior to 56x10.1.100540.65"
}
]
},
{
"vendor": "TAKENAKA ENGINEERING CO., LTD.",
"product": "NVR08T-A",
"versions": [
{
"status": "affected",
"version": "prior to 56x10.1.100540.65"
}
]
},
{
"vendor": "TAKENAKA ENGINEERING CO., LTD.",
"product": "NVR16T-A",
"versions": [
{
"status": "affected",
"version": "prior to 49310.1.100540.65"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:takenaka_engineering:hdvr-400_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "takenaka_engineering",
"product": "hdvr-400_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "46110.1.100869.65",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:takenaka_engineering:hdvr-800_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "takenaka_engineering",
"product": "hdvr-800_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "53210.1.900103.65",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:takenaka_engineering:hdvr-1600_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "takenaka_engineering",
"product": "hdvr-1600_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "53310.1.900111.65",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:takenaka_engineering:ahd04t-a_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "takenaka_engineering",
"product": "ahd04t-a_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "7xx10.1.900055.65",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:takenaka_engineering:ahd08t-a_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "takenaka_engineering",
"product": "ahd08t-a_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "7xx10.1.900055.65",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:takenaka_engineering:ahd16t-a_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "takenaka_engineering",
"product": "ahd16t-a_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "7xx10.1.900055.65",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:takenaka_engineering:nvr04t-a_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "takenaka_engineering",
"product": "nvr04t-a_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "56x10.1.100540.65",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:takenaka_engineering:nvr08t-a_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "takenaka_engineering",
"product": "nvr08t-a_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "56x10.1.100540.65",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:takenaka_engineering:nvr16t-a_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "takenaka_engineering",
"product": "nvr16t-a_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "49310.1.100540.65",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-09-18T07:15:04.220",
"references": [
{
"url": "https://jvn.jp/en/vu/JVNVU90142679/",
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.takex-eng.co.jp/ja/news/news.php?s=68",
"source": "vultures@jpcert.or.jp"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-912"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Hidden functionality issue in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings."
},
{
"lang": "es",
"value": "Un problema de funcionalidad oculta en varias grabadoras de video digitales proporcionadas por TAKENAKA ENGINEERING CO., LTD. permite que un atacante remoto autenticado ejecute un comando de sistema operativo arbitrario en el dispositivo o altere la configuración del dispositivo."
}
],
"lastModified": "2026-06-17T07:56:20.723",
"sourceIdentifier": "vultures@jpcert.or.jp"
}