ZeroHour

CVE-2024-54012

CVSS 4.0
8.5 high
EPSS
<1%p17
Published
()
Modified
Description

Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be executed on the device. The manufacturer has released patch firmware for the flaw; please refer to the manufacturer's report for details and workarounds.

Vendors
hanwhavision
Products
knb-2000 firmware, knb-5000n firmware, knd-2010 firmware, knd-2020rn firmware, knd-2080rn firmware, knd-5020rn firmware, knd-5080rn firmware, kno-2010rn firmware, kno-2080rn firmware, kno-2120rn firmware, kno-5020rn firmware, kno-5080rn firmware
Weakness
CWE-78
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.