Vulnerabilities > CVE-2020-5735 - Out-of-bounds Write vulnerability in Amcrest products

047910
CVSS 8.0 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
COMPLETE
network
low complexity
amcrest
CWE-787
exploit available

Summary

Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.

Common Weakness Enumeration (CWE)

Exploit-Db

idEDB-ID:48304
last seen2020-04-08
modified2020-04-08
published2020-04-08
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/48304
titleAmcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/157164/amcrestdahuanvr-dos.txt
idPACKETSTORM:157164
last seen2020-04-13
published2020-04-08
reporterJacob Baines
sourcehttps://packetstormsecurity.com/files/157164/Amcrest-Dahua-NVR-Camera-IP2M-841-Denial-Of-Service.html
titleAmcrest Dahua NVR Camera IP2M-841 Denial Of Service