CVE-2019-11878: Integer Overflow
An issue was discovered on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras. An attacker on the same local network as the camera can craft a message with a size field larger than 0x80000000 and send it to the camera, related to an integer overflow or use of a negative number. This then crashes the camera for about 120 seconds.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11878?
CVE-2019-11878 is a vulnerability found on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras.
What is the severity of CVE-2019-11878?
CVE-2019-11878 has a severity value of 6.5, which is considered medium.
How does CVE-2019-11878 affect XiongMai Besder IP20H1 cameras?
CVE-2019-11878 allows an attacker on the same local network as the camera to craft a malicious message, leading to an integer overflow or use of a negative number.
How can an attacker exploit CVE-2019-11878?
An attacker can exploit CVE-2019-11878 by sending a crafted message with a size field larger than 0x80000000 to the camera on the same local network.
Are XiongMai Besder IP20H1 cameras vulnerable to CVE-2019-11878?
Yes, XiongMai Besder IP20H1 cameras with firmware version 4.02.r12.00035520.12012.047500.00200 are vulnerable to CVE-2019-11878.