CVE-2023-5037: Authenticated Command Injection
badmonkey, a Security Researcher has found a flaw that allows for a authenticated command injection on the camera. An attacker could inject malicious into request packets to execute command. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5037?
CVE-2023-5037 has been rated with a high severity due to the potential for authenticated command injection vulnerabilities in various Hanwhavision camera firmware versions.
How do I fix CVE-2023-5037?
To address CVE-2023-5037, users should update their affected Hanwhavision camera firmware to the patched version released by the manufacturer.
What types of attacks are possible due to CVE-2023-5037?
CVE-2023-5037 allows attackers to perform authenticated command injection, potentially enabling them to execute arbitrary commands on the affected camera.
Which Hanwhavision camera models are affected by CVE-2023-5037?
CVE-2023-5037 affects a number of Hanwhavision camera models including Ano, Anv, Ane, and others running specific firmware versions prior to the identified patch.
Has a patch for CVE-2023-5037 been released?
Yes, the manufacturer has released updated firmware to address the vulnerabilities associated with CVE-2023-5037.