CVE-2024-54012: Command Injection
Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be executed on the device. The manufacturer has released patch firmware for the flaw; please refer to the manufacturer's report for details and workarounds.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54012?
CVE-2024-54012 has a high severity rating of 8.5 according to the CVSS system.
What type of vulnerability is CVE-2024-54012?
CVE-2024-54012 is classified as a Command Injection vulnerability.
How can I mitigate CVE-2024-54012?
To mitigate CVE-2024-54012, users should update to the latest patch firmware released by the manufacturer.
What devices are affected by CVE-2024-54012?
CVE-2024-54012 affects various models of HanwhaVision camera systems including Knb-2000, Knd-2010, and others.
Is there a permanent fix for CVE-2024-54012?
Yes, a permanent fix for CVE-2024-54012 is available through the updated firmware provided by the manufacturer.