CVE-2023-5038

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/06/2024
Last modified:
02/07/2024

Description

badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody can access the web management page of the camera. and must manually restart the device or re-power it. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hanwhavision:ano-l6012r_firmware:*:*:*:*:*:*:*:* 1.41.16 (excluding)
cpe:2.3:h:hanwhavision:ano-l6012r:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:ano-l6022r_firmware:*:*:*:*:*:*:*:* 1.41.16 (excluding)
cpe:2.3:h:hanwhavision:ano-l6022r:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:anv-l6012r_firmware:*:*:*:*:*:*:*:* 1.41.16 (excluding)
cpe:2.3:h:hanwhavision:anv-l6012r:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:ano-l6082r_firmware:*:*:*:*:*:*:*:* 1.41.16 (excluding)
cpe:2.3:h:hanwhavision:ano-l6082r:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:ane-l6012r_firmware:*:*:*:*:*:*:*:* 1.41.16 (excluding)
cpe:2.3:h:hanwhavision:ane-l6012r:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:anv-l6082r_firmware:*:*:*:*:*:*:*:* 1.41.16 (excluding)
cpe:2.3:h:hanwhavision:anv-l6082r:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:ano-l7082r_firmware:*:*:*:*:*:*:*:* 1.41.16 (excluding)
cpe:2.3:h:hanwhavision:ano-l7082r:-:*:*:*:*:*:*:*
cpe:2.3:o:hanwhavision:ane-l7012r_firmware:*:*:*:*:*:*:*:* 1.41.16 (excluding)