CVE-2020-5736: Null Pointer Dereference
Published Apr 8, 2020
·Updated
Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device.
Affected Software
72 affected components
Amcrest 1080-lite 8ch Firmware
Amcrest 1080-lite 8ch
Amcrest Amdv10814-h5 Firmware
Amcrest Amdv10814-h5
Amcrest Ipm-721 Firmware<v2.420.ac00.18.r.20200217
Amcrest Ipm-721
Amcrest Ip2m-841 Firmware<v2.420.ac00.18.r.20200217
Amcrest Ip2m-841
Amcrest Ip2m-841-v3 Firmware<v2.800.0000000.6.r.200314
Amcrest Ip2m-841-v3
Amcrest Ip2m-853ew Firmware<v2.623.00ac004.0.r.200316
Amcrest Ip2m-853ew
Amcrest Ip2m-858w Firmware<v2.623.00ac004.0.r.200316
Amcrest Ip2m-858w
Amcrest Ip2m-866w Firmware<v2.623.00ac004.0.r.200316
Amcrest Ip2m-866w
Amcrest Ip2m-866ew Firmware<v2.623.00ac004.0.r.200316
Amcrest Ip2m-866ew
Amcrest Ip4m-1053ew Firmware<v2.623.00ac004.0.r.200316
Amcrest Ip4m-1053ew
Amcrest Ip8m-2454ew Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-2454ew
Amcrest Ip8m-2493eb Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-2493eb
Amcrest Ip8m-2496eb Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-2496eb
Amcrest Ip8m-2597e Firmware<v2.800.00ac000.0.r.200330
Amcrest Ip8m-2597e
Amcrest Ip8m-mb2546ew Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-mb2546ew
Amcrest Ip8m-mt2544ew Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-mt2544ew
Amcrest Ip8m-t2499ew Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-t2499ew
Amcrest Ipm-hx1 Firmware<v2.420.ac00.18.r.20200217
Amcrest Ipm-hx1
All of the following
Amcrest 1080-lite 8ch Firmware
Amcrest 1080-lite 8ch
All of the following
Amcrest Amdv10814-h5 Firmware
Amcrest Amdv10814-h5
All of the following
Amcrest Ipm-721 Firmware<v2.420.ac00.18.r.20200217
Amcrest Ipm-721
All of the following
Amcrest Ip2m-841 Firmware<v2.420.ac00.18.r.20200217
Amcrest Ip2m-841
All of the following
Amcrest Ip2m-841-v3 Firmware<v2.800.0000000.6.r.200314
Amcrest Ip2m-841-v3
All of the following
Amcrest Ip2m-853ew Firmware<v2.623.00ac004.0.r.200316
Amcrest Ip2m-853ew
All of the following
Amcrest Ip2m-858w Firmware<v2.623.00ac004.0.r.200316
Amcrest Ip2m-858w
All of the following
Amcrest Ip2m-866w Firmware<v2.623.00ac004.0.r.200316
Amcrest Ip2m-866w
All of the following
Amcrest Ip2m-866ew Firmware<v2.623.00ac004.0.r.200316
Amcrest Ip2m-866ew
All of the following
Amcrest Ip4m-1053ew Firmware<v2.623.00ac004.0.r.200316
Amcrest Ip4m-1053ew
All of the following
Amcrest Ip8m-2454ew Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-2454ew
All of the following
Amcrest Ip8m-2493eb Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-2493eb
All of the following
Amcrest Ip8m-2496eb Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-2496eb
All of the following
Amcrest Ip8m-2597e Firmware<v2.800.00ac000.0.r.200330
Amcrest Ip8m-2597e
All of the following
Amcrest Ip8m-mb2546ew Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-mb2546ew
All of the following
Amcrest Ip8m-mt2544ew Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-mt2544ew
All of the following
Amcrest Ip8m-t2499ew Firmware<v2.622.00ac000.0.r.200320
Amcrest Ip8m-t2499ew
All of the following
Amcrest Ipm-hx1 Firmware<v2.420.ac00.18.r.20200217
Amcrest Ipm-hx1
Event History
Apr 8, 2020
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-5736.
2
What software is affected by this vulnerability?
Amcrest cameras and NVR are affected by this vulnerability.
3
What is the severity of CVE-2020-5736?
The severity of CVE-2020-5736 is medium with a CVSS score of 6.5.
4
How does this vulnerability affect Amcrest cameras and NVR?
This vulnerability can be exploited by an authenticated remote attacker to crash the device.
5
Is there a fix available for CVE-2020-5736?
Yes, please refer to the vendor for the necessary patches or updates to fix CVE-2020-5736.