CVE-2018-19864
critical · 9.8NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device.
9.8
CVSS
24.8%
EPSS (exploit prob.)
98th
EPSS percentile
2018-12-05
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-20CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| nuuo | nvrmini2_firmware | <= 3.9.1 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/153162/NUUO-NVRMini-2-3.9.1-Stack-Overflow.html
- https://www.digitaldefense.com/blog/zero-day-alerts/nuuo-firmware-disclosure/
- https://www.nuuo.com/DownloadMainpage.php
- http://packetstormsecurity.com/files/153162/NUUO-NVRMini-2-3.9.1-Stack-Overflow.html
- https://www.digitaldefense.com/blog/zero-day-alerts/nuuo-firmware-disclosure/
- https://www.nuuo.com/DownloadMainpage.php
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-19864