CVE-2024-54012
—CVSS 4.0
8.5 high
EPSS
<1%p17
Published
()
Modified
Description
Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be executed on the device. The manufacturer has released patch firmware for the flaw; please refer to the manufacturer's report for details and workarounds.
- Vendors
- hanwhavision
- Products
- knb-2000 firmware, knb-5000n firmware, knd-2010 firmware, knd-2020rn firmware, knd-2080rn firmware, knd-5020rn firmware, knd-5080rn firmware, kno-2010rn firmware, kno-2080rn firmware, kno-2120rn firmware, kno-5020rn firmware, kno-5080rn firmware
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.