CVE-2020-24214
critical · 9.8An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash. The device will not be able to perform its main purpose of video encoding and streaming for up to a minute, until it automatically reboots. Attackers can send malicious requests once a minute, effectively disabling the device.
9.8
CVSS
35.4%
EPSS (exploit prob.)
98th
EPSS percentile
2020-10-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| szuray | iptv/h.264_video_encoder_firmware | all versions |
| szuray | uaioe264-1u | all versions |
| szuray | uce264-1-mini | all versions |
| szuray | uce264-1wb-mini | all versions |
| szuray | uce264-4-1u | all versions |
| szuray | uce264-8-1u | all versions |
| szuray | uhae264-16 | all versions |
| szuray | uhce264-1 | all versions |
| szuray | uhce264-16p32 | all versions |
| szuray | uhce264-1p2 | all versions |
| szuray | uhce264-1p2-1u | all versions |
| szuray | uhce264-1s | all versions |
| szuray | uhce264-1w | all versions |
| szuray | uhce264-1ws | all versions |
| szuray | uhce264-4p8 | all versions |
| szuray | uhe264-1-4k | all versions |
| szuray | uhe264-16 | all versions |
| szuray | uhe264-16l-3u | all versions |
| szuray | uhe264-16s-2u | all versions |
| szuray | uhe264-1l | all versions |
| szuray | uhe264-1l-4k | all versions |
| szuray | uhe264-1lw | all versions |
| szuray | uhe264-1s | all versions |
| szuray | uhe264-1s-mini | all versions |
| szuray | uhe264-1w-mini | all versions |
| szuray | uhe264-1wb-4g | all versions |
| szuray | uhe264-1wb-mini | all versions |
| szuray | uhe264-1wbs-2b | all versions |
| szuray | uhe264-1wbs-mini | all versions |
| szuray | uhe264-1ws-mini | all versions |
| szuray | uhe264-2-1u | all versions |
| szuray | uhe264-4 | all versions |
| szuray | uhe264-4-1u | all versions |
| szuray | uhe264-4l-1u | all versions |
| szuray | uhe264-8 | all versions |
| szuray | uhe264-8-1u | all versions |
| szuray | uhe264-8l-3u | all versions |
| szuray | uhe264-8s-2u | all versions |
| szuray | use264-16-3u | all versions |
| szuray | use264-1l | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/159605/HiSilicon-Video-Encoder-Buffer-Overflow-Denial-Of-Service.html
- https://kojenov.com/2020-09-15-hisilicon-encoder-vulnerabilities/
- https://www.kb.cert.org/vuls/id/896979
- http://packetstormsecurity.com/files/159605/HiSilicon-Video-Encoder-Buffer-Overflow-Denial-Of-Service.html
- https://kojenov.com/2020-09-15-hisilicon-encoder-vulnerabilities/
- https://www.kb.cert.org/vuls/id/896979
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-24214