CVE-2020-5735
high · 8.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-11-03Remediation due 2022-05-03
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.
8.8
CVSS
36.2%
EPSS (exploit prob.)
98th
EPSS percentile
2020-04-08
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-121CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| amcrest | 1080-lite_8ch_firmware | all versions |
| amcrest | 1080-lite_8ch | all versions |
| amcrest | amdv10814-h5_firmware | all versions |
| amcrest | amdv10814-h5 | all versions |
| amcrest | ipm-721_firmware | < v2.420.ac00.18.r.20200217 |
| amcrest | ipm-721 | all versions |
| amcrest | ip2m-841_firmware | < v2.420.ac00.18.r.20200217 |
| amcrest | ip2m-841 | all versions |
| amcrest | ip2m-841-v3_firmware | < v2.800.0000000.6.r.200314 |
| amcrest | ip2m-841-v3 | all versions |
| amcrest | ip2m-853ew_firmware | < v2.623.00ac004.0.r.200316 |
| amcrest | ip2m-853ew | all versions |
| amcrest | ip2m-858w_firmware | < v2.623.00ac004.0.r.200316 |
| amcrest | ip2m-858w | all versions |
| amcrest | ip2m-866w_firmware | < v2.623.00ac004.0.r.200316 |
| amcrest | ip2m-866w | all versions |
| amcrest | ip2m-866ew_firmware | < v2.623.00ac004.0.r.200316 |
| amcrest | ip2m-866ew | all versions |
| amcrest | ip4m-1053ew_firmware | < v2.623.00ac004.0.r.200316 |
| amcrest | ip4m-1053ew | all versions |
| amcrest | ip8m-2454ew_firmware | < v2.622.00ac000.0.r.200320 |
| amcrest | ip8m-2454ew | all versions |
| amcrest | ip8m-2493eb_firmware | < v2.622.00ac000.0.r.200320 |
| amcrest | ip8m-2493eb | all versions |
| amcrest | ip8m-2496eb_firmware | < v2.622.00ac000.0.r.200320 |
| amcrest | ip8m-2496eb | all versions |
| amcrest | ip8m-2597e_firmware | < v2.800.00ac000.0.r.200330 |
| amcrest | ip8m-2597e | all versions |
| amcrest | ip8m-mb2546ew_firmware | < v2.622.00ac000.0.r.200320 |
| amcrest | ip8m-mb2546ew | all versions |
| amcrest | ip8m-mt2544ew_firmware | < v2.622.00ac000.0.r.200320 |
| amcrest | ip8m-mt2544ew | all versions |
| amcrest | ip8m-t2499ew_firmware | < v2.622.00ac000.0.r.200320 |
| amcrest | ip8m-t2499ew | all versions |
| amcrest | ipm-hx1_firmware | < v2.420.ac00.18.r.20200217 |
| amcrest | ipm-hx1 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/157164/Amcrest-Dahua-NVR-Camera-IP2M-841-Denial-Of-Service.html
- https://www.tenable.com/security/research/tra-2020-20
- http://packetstormsecurity.com/files/157164/Amcrest-Dahua-NVR-Camera-IP2M-841-Denial-Of-Service.html
- https://www.tenable.com/security/research/tra-2020-20
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5735
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-5735