First published: Wed Apr 08 2020(Updated: )
Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amcrest 1080-lite 8ch Firmware | ||
Amcrest 1080-lite 8ch Firmware | ||
Amcrest Amdv10814-h5 Firmware | ||
Amcrest Amdv10814-h5 Firmware | ||
Amcrest IPM-721 | <v2.420.ac00.18.r.20200217 | |
Amcrest Ipm-721 Firmware | ||
Amcrest IP2M-841B Firmware | <v2.420.ac00.18.r.20200217 | |
Amcrest IP2M-841W | ||
Amcrest IP2M-841 | <v2.800.0000000.6.r.200314 | |
Amcrest IP2M-841-V3 Firmware | ||
Amcrest IP2M-853EW | <v2.623.00ac004.0.r.200316 | |
Amcrest IP2M-853EW Firmware | ||
Amcrest IP2M-858W | <v2.623.00ac004.0.r.200316 | |
Amcrest Ip2m-858w Firmware | ||
Amcrest Ip2m-866w Firmware | <v2.623.00ac004.0.r.200316 | |
Amcrest IP2M-866W | ||
Amcrest IP2M-866EW | <v2.623.00ac004.0.r.200316 | |
Amcrest Ip2m-866ew Firmware | ||
Amcrest Ip4m-1053ew Firmware | <v2.623.00ac004.0.r.200316 | |
Amcrest Ip4m-1053ew Firmware | ||
Amcrest IP8M-2454EW | <v2.622.00ac000.0.r.200320 | |
Amcrest IP8M-2454EW | ||
Amcrest IP8M-2493EB Firmware | <v2.622.00ac000.0.r.200320 | |
Amcrest IP8M-2493EB | ||
Amcrest Ip8m-2496eb Firmware | <v2.622.00ac000.0.r.200320 | |
Amcrest IP8M-2496EB | ||
Amcrest Ip8m-2597e Firmware | <v2.800.00ac000.0.r.200330 | |
Amcrest IP8M-2597E | ||
Amcrest IP8M-MB2546EW | <v2.622.00ac000.0.r.200320 | |
Amcrest IP8M-MB2546EW | ||
Amcrest Ip8m-mt2544ew | <v2.622.00ac000.0.r.200320 | |
Amcrest Ip8m-mt2544ew Firmware | ||
Amcrest IP8M-T2499EW | <v2.622.00ac000.0.r.200320 | |
Amcrest Ip8m-t2499ew Firmware | ||
Amcrest IPC-HX1X3X | <v2.420.ac00.18.r.20200217 | |
Amcrest Ipm-hx1 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-5736.
Amcrest cameras and NVR are affected by this vulnerability.
The severity of CVE-2020-5736 is medium with a CVSS score of 6.5.
This vulnerability can be exploited by an authenticated remote attacker to crash the device.
Yes, please refer to the vendor for the necessary patches or updates to fix CVE-2020-5736.