CVE-2019-3948
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.
Published:Jul 29, 2019
Last Modified:Nov 21, 2024
EPS:Jul 29, 2019
EPSS Score:0.37992
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Amcrest
Product
Ip2m-841b
Amcrest
Ip2m-841b
Vendor
Amcrest
Product
Ip2m-841b Firmware
Amcrest
Ip2m-841b Firmware
Vendor
Dahua
Product
Dh-ipc-hx863x
Dahua
Dh-ipc-hx863x
Vendor
Dahua
Product
Dh-ipc-hx883x
Dahua
Dh-ipc-hx883x
Vendor
Dahua
Product
Dh-sd4xxxxx
Dahua
Dh-sd4xxxxx
Vendor
Dahua
Product
Dh-sd5xxxxx
Dahua
Dh-sd5xxxxx
Vendor
Dahua
Product
Dh-sd6xxxxx
Dahua
Dh-sd6xxxxx
Vendor
Dahua
Product
Ipc-hx4x3x
Dahua
Ipc-hx4x3x
Vendor
Dahua
Product
Ipc-hx5x3x
Dahua
Ipc-hx5x3x
Vendor
Dahua
Product
Ipc-xxbxx
Dahua
Ipc-xxbxx
Vendor
Dahua
Product
Nvr2xxx-4ks2
Dahua
Nvr2xxx-4ks2
Vendor
Dahua
Product
Nvr4xxx-4ks2
Dahua
Nvr4xxx-4ks2
Vendor
Dahua
Product
Nvr5xxx-4ks2
Dahua
Nvr5xxx-4ks2
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
