CVE-2019-3948
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
29/07/2019
Last modified:
24/08/2020
Description
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:amcrest:ip2m-841b_firmware:2.520.ac00.18.r:*:*:*:*:*:*:* | ||
cpe:2.3:h:amcrest:ip2m-841b:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:dahua:dh-ipc-hx863x:*:*:*:*:*:*:*:* | 2018-05-18 (excluding) | |
cpe:2.3:o:dahua:dh-ipc-hx883x:*:*:*:*:*:*:*:* | 2018-05-18 (excluding) | |
cpe:2.3:o:dahua:dh-sd4xxxxx:*:*:*:*:*:*:*:* | 2018-05-18 (excluding) | |
cpe:2.3:o:dahua:dh-sd5xxxxx:*:*:*:*:*:*:*:* | 2018-05-18 (excluding) | |
cpe:2.3:o:dahua:dh-sd6xxxxx:*:*:*:*:*:*:*:* | 2018-05-18 (excluding) | |
cpe:2.3:o:dahua:ipc-hx4x3x:*:*:*:*:*:*:*:* | 2018-05-18 (excluding) | |
cpe:2.3:o:dahua:ipc-hx5x3x:*:*:*:*:*:*:*:* | 2018-05-18 (excluding) | |
cpe:2.3:o:dahua:ipc-xxbxx:*:*:*:*:*:*:*:* | 2018-05-18 (excluding) | |
cpe:2.3:o:dahua:nvr2xxx-4ks2:*:*:*:*:*:*:*:* | 2018-05-18 (excluding) | |
cpe:2.3:o:dahua:nvr4xxx-4ks2:*:*:*:*:*:*:*:* | 2018-05-18 (excluding) | |
cpe:2.3:o:dahua:nvr5xxx-4ks2:*:*:*:*:*:*:*:* | 2018-05-18 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/153813/Amcrest-Cameras-2.520.AC00.18.R-Unauthenticated-Audio-Streaming.html
- https://us.dahuasecurity.com/wp-content/uploads/2019/08/Cybersecurity_2019-08-02.pdf
- https://www.dahuasecurity.com/support/cybersecurity/details/627?us=
- https://www.tenable.com/security/research/tra-2019-36