CVE-2019-11878 Information

Description

An issue was discovered on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras. An attacker on the same local network as the camera can craft a message with a size field larger than 0x80000000 and send it to the camera related to an integer overflow or use of a negative number. This then crashes the camera for about 120 seconds.

CVSS Vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

http://blog.0x42424242.in/2019/04/besder-investigative-journey-part-1_24.html https://www.youtube.com/watch?v=SnyPJtDDMFQ

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

6.5

Share on: