Vulnerabilities > CVE-2020-24214

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
szuray
jtechdigital
provideoinstruments
critical

Summary

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash. The device will not be able to perform its main purpose of video encoding and streaming for up to a minute, until it automatically reboots. Attackers can send malicious requests once a minute, effectively disabling the device.

Vulnerable Configurations

Part Description Count
OS
Szuray
2
OS
Jtechdigital
1
OS
Provideoinstruments
4
Hardware
Szuray
93
Hardware
Jtechdigital
1
Hardware
Provideoinstruments
4