CVE-2020-5736

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
08/04/2020
Last modified:
09/04/2020

Description

Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:amcrest:1080-lite_8ch_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amcrest:1080-lite_8ch:-:*:*:*:*:*:*:*
cpe:2.3:o:amcrest:amdv10814-h5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amcrest:amdv10814-h5:-:*:*:*:*:*:*:*
cpe:2.3:o:amcrest:ipm-721_firmware:*:*:*:*:*:*:*:* v2.420.ac00.18.r.20200217 (excluding)
cpe:2.3:h:amcrest:ipm-721:-:*:*:*:*:*:*:*
cpe:2.3:o:amcrest:ip2m-841_firmware:*:*:*:*:*:*:*:* v2.420.ac00.18.r.20200217 (excluding)
cpe:2.3:h:amcrest:ip2m-841:-:*:*:*:*:*:*:*
cpe:2.3:o:amcrest:ip2m-841-v3_firmware:*:*:*:*:*:*:*:* v2.800.0000000.6.r.200314 (excluding)
cpe:2.3:h:amcrest:ip2m-841-v3:-:*:*:*:*:*:*:*
cpe:2.3:o:amcrest:ip2m-853ew_firmware:*:*:*:*:*:*:*:* v2.623.00ac004.0.r.200316 (excluding)
cpe:2.3:h:amcrest:ip2m-853ew:-:*:*:*:*:*:*:*
cpe:2.3:o:amcrest:ip2m-858w_firmware:*:*:*:*:*:*:*:* v2.623.00ac004.0.r.200316 (excluding)
cpe:2.3:h:amcrest:ip2m-858w:-:*:*:*:*:*:*:*
cpe:2.3:o:amcrest:ip2m-866w_firmware:*:*:*:*:*:*:*:* v2.623.00ac004.0.r.200316 (excluding)


References to Advisories, Solutions, and Tools