Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777
Published Apr 8, 2020 ·Due May 3, 2022
8.8
HIGHCVSS 3.1
EPSS 36.22%
Description
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.
Affected products
- Vendor n/a Product Amcrest Defaultn/a
- Version before 2.623.00AC004.0.R.200316, 2.420.AC00.18.R.20200217, 2.800.00AC000.0.R.200330, 2.800.0000000.6.R.200314.bin, 2.622.00AC000.0.R.200320.bin, and 4.000.00AC000.0.R.200218StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Amcrest | n/a |
|
Configuration 1
- n/a
Running on/with
- n/a
Configuration 2
- n/a
Running on/with
- n/a
Configuration 3
- < v2.420.ac00.18.r.20200217
Configuration 4
- < v2.420.ac00.18.r.20200217
Configuration 5
- < v2.800.0000000.6.r.200314
Running on/with
- n/a
Configuration 6
- < v2.623.00ac004.0.r.200316
Running on/with
- n/a
Configuration 7
- < v2.623.00ac004.0.r.200316
Configuration 8
- < v2.623.00ac004.0.r.200316
Configuration 9
- < v2.623.00ac004.0.r.200316
Running on/with
- n/a
Configuration 10
- < v2.623.00ac004.0.r.200316
Running on/with
- n/a
Configuration 11
- < v2.622.00ac000.0.r.200320
Running on/with
- n/a
Configuration 12
- < v2.622.00ac000.0.r.200320
Running on/with
- n/a
Configuration 13
- < v2.622.00ac000.0.r.200320
Running on/with
- n/a
Configuration 14
- < v2.800.00ac000.0.r.200330
Running on/with
- n/a
Configuration 15
- < v2.622.00ac000.0.r.200320
Running on/with
- n/a
Configuration 16
- < v2.622.00ac000.0.r.200320
Running on/with
- n/a
Configuration 17
- < v2.622.00ac000.0.r.200320
Running on/with
- n/a
Configuration 18
- < v2.420.ac00.18.r.20200217
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- http://packetstormsecurity.com/files/157164/Amcrest-Dahua-NVR-Camera-IP2M-841-Denial-Of-Service.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-26894 Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5735 government-resourceUS Government Resource
- https://www.tenable.com/security/research/tra-2020-20 x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/157164/Amcrest-Dahua-NVR-Camera-IP2M-841-Denial-Of-Service.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-26894 | Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5735 | government-resourceUS Government Resource | |
| https://www.tenable.com/security/research/tra-2020-20 | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.