CVE-2023-5038: Unauthenticated DoS
badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody can access the web management page of the camera. and must manually restart the device or re-power it. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5038?
CVE-2023-5038 has been assessed with a critical severity due to its potential for an unauthenticated denial of service (DoS) attack on camera devices.
How do I fix CVE-2023-5038?
To mitigate CVE-2023-5038, upgrade the firmware of affected Hanwhavision camera models to version 1.41.16 or later.
Which devices are affected by CVE-2023-5038?
CVE-2023-5038 affects various Hanwhavision camera models, including the Ano-L6012R, Ano-L6022R, Anv-L6012R, and others with firmware versions prior to 1.41.16.
What kind of attack does CVE-2023-5038 enable?
CVE-2023-5038 allows attackers to execute an unauthenticated denial of service (DoS) attack, rendering the camera management page inaccessible.
What should I do if my device is affected by CVE-2023-5038?
If your device is affected by CVE-2023-5038, ensure you promptly apply the latest firmware updates provided by the manufacturer to protect against the vulnerability.