CVE Feed

    Dashboard / CVE / CVE-2022-2471

    CVE-2022-2471

    Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-C6N-A0-1C2WFR, CS-DB1C-A0-1E2W2FR, CS-C6N-B0-1G2WF, CS-C3W-A0-3H4WFRL allows a remote attacker to execute remote code on the device. This issue affects: EZVIZ CS-CV248 versions prior to 5.2.3 build 220725. EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428. EZVIZ CS-DB1C-A0-1E2W2FR versions prior to 5.3.0 build 220802. EZVIZ CS-C6N-B0-1G2WF versions prior to 5.3.0 build 220712. EZVIZ CS-C3W-A0-3H4WFRL versions prior to 5.3.5 build 220723.

    Published:Sep 15, 2022
    Last Modified:Nov 21, 2024
    EPS:Sep 15, 2022
    EPSS Score:0.01741
    CVSS Score:9.9

    Affected Products

    Vendor
    Ezviz
    Product
    Cs-c3w-a0-3h4wfrl
    Vendor
    Ezviz
    Product
    Cs-c3w-a0-3h4wfrl Firmware
    Vendor
    Ezviz
    Product
    Cs-c6n-a0-1c2wfr
    Vendor
    Ezviz
    Product
    Cs-c6n-a0-1c2wfr Firmware
    Vendor
    Ezviz
    Product
    Cs-c6n-b0-1g2wf
    Vendor
    Ezviz
    Product
    Cs-c6n-b0-1g2wf Firmware
    Vendor
    Ezviz
    Product
    Cs-cv248
    Vendor
    Ezviz
    Product
    Cs-cv248 Firmware
    Vendor
    Ezviz
    Product
    Cs-db1c-a0-1e2w2fr
    Vendor
    Ezviz
    Product
    Cs-db1c-a0-1e2w2fr Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High