First published: Mon Mar 13 2017(Updated: )
Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the SDK issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hikvision DS-76xxx Series Firmware | <=3.3.4 | |
Hikvision DS-7604NI-E1/4P | ||
Hikvision DS-7608NI-12/8P | ||
Hikvision DS-7608NI-E1/8P | ||
Hikvision DS-7616NI-12/16P | ||
Hikvision DS-7616NI-E2/16P | ||
Hikvision DS-77xxx Series Firmware | <=3.3.4 | |
Hikvision DS-7716NI-14/16P | ||
Hikvision DS-7716NI-SP/16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4409 has a high severity rating due to its potential to cause denial of service where remote authenticated users can crash the affected devices.
To fix CVE-2015-4409, update the Hikvision NVR firmware to version 3.4.0 or later.
CVE-2015-4409 affects Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices running firmware versions prior to 3.4.0.
Yes, CVE-2015-4409 can be exploited remotely by authenticated users through specially crafted HTTP requests.
The main impact of CVE-2015-4409 is a denial of service, which results in a temporary interruption of NVR services.