First published: Mon Mar 13 2017(Updated: )
Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the ISAPI issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hikvision DS-76xxx Series Firmware | <=3.3.4 | |
Hikvision DS-7604NI-E1/4P | ||
Hikvision DS-7608NI-12/8P | ||
Hikvision DS-7608NI-E1/8P | ||
Hikvision DS-7616NI-12/16P | ||
Hikvision DS-7616NI-E2/16P | ||
Hikvision DS-77xxx Series Firmware | <=3.3.4 | |
Hikvision DS-7716NI-14/16P | ||
Hikvision DS-7716NI-SP/16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4408 has a high severity level as it allows remote authenticated users to cause a denial of service.
To fix CVE-2015-4408, update the firmware of affected Hikvision devices to version 3.4.0 or later.
CVE-2015-4408 affects the Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices running firmware versions up to 3.3.4.
Yes, CVE-2015-4408 can be exploited remotely by authenticated users through a specially crafted HTTP request.
CVE-2015-4408 is classified as a buffer overflow vulnerability.