CVE Feed

    Dashboard / CVE / CVE-2019-3948

    CVE-2019-3948

    The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.

    Published:Jul 29, 2019
    Last Modified:Nov 21, 2024
    EPS:Jul 29, 2019
    EPSS Score:0.37992
    CVSS Score:7.5

    Affected Products

    Vendor
    Amcrest
    Product
    Ip2m-841b
    Vendor
    Amcrest
    Product
    Ip2m-841b Firmware
    Vendor
    Dahua
    Product
    Dh-ipc-hx863x
    Vendor
    Dahua
    Product
    Dh-ipc-hx883x
    Vendor
    Dahua
    Product
    Dh-sd4xxxxx
    Vendor
    Dahua
    Product
    Dh-sd5xxxxx
    Vendor
    Dahua
    Product
    Dh-sd6xxxxx
    Vendor
    Dahua
    Product
    Ipc-hx4x3x
    Vendor
    Dahua
    Product
    Ipc-hx5x3x
    Vendor
    Dahua
    Product
    Ipc-xxbxx
    Vendor
    Dahua
    Product
    Nvr2xxx-4ks2
    Vendor
    Dahua
    Product
    Nvr4xxx-4ks2
    Vendor
    Dahua
    Product
    Nvr5xxx-4ks2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High