CVE-2020-24055
Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binary executable '/usr/sbin/DM' that listens on port TCP 6666. The service is vulnerable to a stack buffer overflow. It is worth noting that this service does not require any authentication.
Published:Aug 21, 2020
Last Modified:Nov 21, 2024
EPS:Aug 21, 2020
EPSS Score:0.00495
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Verint
Product
4320
Verint
4320
Vendor
Verint
Product
4320 Firmware
Verint
4320 Firmware
Vendor
Verint
Product
5620ptz
Verint
5620ptz
Vendor
Verint
Product
5620ptz Firmware
Verint
5620ptz Firmware
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
