10

CVE-2017-16725

A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based buffer overflow vulnerability has been identified, which may allow an attacker to execute code remotely or crash the device. After rebooting, the device restores itself to a more vulnerable state in which Telnet is accessible.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
XiongmaitechAhb7008f8-h Firmware Version4.02.r11.3070
   XiongmaitechAhb7008f8-h Version-
XiongmaitechAhb7008f4-h Firmware Version4.02.r11.3070
   XiongmaitechAhb7008f4-h Version-
XiongmaitechAhb7008f2-h Firmware Version4.02.r11.3070
   XiongmaitechAhb7008f2-h Version-
XiongmaitechAhb7008t-mh-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008t-mh-v2 Version-
XiongmaitechAhb7004t-mh-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7004t-mh-v2 Version-
XiongmaitechAhb7004t-h-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7004t-h-v2 Version-
XiongmaitechAhb7016t-lm-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7016t-lm-v2 Version-
XiongmaitechAhb7008t-lm-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008t-lm-v2 Version-
XiongmaitechAhb7016t4-mh-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7016t4-mh-v2 Version-
XiongmaitechAhb7016t-mh-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7016t-mh-v2 Version-
XiongmaitechAhb7008t4-h-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008t4-h-v2 Version-
XiongmaitechAhb7008t-h-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008t-h-v2 Version-
XiongmaitechAhb7008t4-h-v2 Version_firmware Update4.02.r11.7601
   XiongmaitechAhb7008t4-h-v2 Version-
XiongmaitechAhb7008t-h-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008t-h-v2 Version-
XiongmaitechAhb7032f8-lm-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7032f8-lm-v2 Version-
XiongmaitechAhb7032f4-lm-v2 Firmware Version4.02.r11.7601
   XiongmaitechAhb7032f4-lm-v2 Version-
XiongmaitechAhb7808r-ms-v3 Firmware Version4.02.r11.nat.onvifc.20170327
   XiongmaitechAhb7808r-ms-v3 Version-
XiongmaitechAhb7804r-ms-v3 Firmware Version4.02.r11.nat.onvifc.20170327
   XiongmaitechAhb7804r-ms-v3 Version-
XiongmaitechAhb7016t-lm-v3 Firmware Version4.02.r11.3070
   XiongmaitechAhb7016t-lm-v3 Version-
XiongmaitechAhb7008t-lm-v3 Firmware Version4.02.r11.3070
   XiongmaitechAhb7008t-lm-v3 Version-
XiongmaitechAhb7004t-lm-v3 Firmware Version4.02.r11.3070
   XiongmaitechAhb7004t-lm-v3 Version-
XiongmaitechAhb7016t4-gs-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7016t4-gs-v3 Version-
XiongmaitechAhb7016t-gs-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7016t-gs-v3 Version-
XiongmaitechAhb7008t-gs-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008t-gs-v3 Version-
XiongmaitechAhb7004t-gs-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7004t-gs-v3 Version-
XiongmaitechAhb7016t-mh-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7016t-mh-v3 Version-
XiongmaitechAhb7008t-mh-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008t-mh-v3 Version-
XiongmaitechAhb7004t-mh-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7004t-mh-v3 Version-
XiongmaitechAhb7008t-gl-v4 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008t-gl-v4 Version-
XiongmaitechAhb7004t-gl-v4 Firmware Version4.02.r11.7601
   XiongmaitechAhb7004t-gl-v4 Version-
XiongmaitechAhb7004t-g-v4 Firmware Version4.02.r11.7601
   XiongmaitechAhb7004t-g-v4 Version-
XiongmaitechAhb7016f8-gs-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7016f8-gs-v3 Version-
XiongmaitechAhb7016f8-gl-v4 Firmware Version4.02.r11.7601
   XiongmaitechAhb7016f8-gl-v4 Version-
XiongmaitechAhb7016f4-gl-v4 Firmware Version4.02.r11.7601
   XiongmaitechAhb7016f4-gl-v4 Version-
XiongmaitechAhb7016f2-gl-v4 Firmware Version4.02.r11.7601
   XiongmaitechAhb7016f2-gl-v4 Version-
XiongmaitechAhb7808r-lm-v3 Firmware Version4.02.r11.nat.onvifc.20171120
   XiongmaitechAhb7808r-lm-v3 Version-
XiongmaitechAhb7804r-lm-v3 Firmware Version4.02.r11.nat.onvifc.20171120
   XiongmaitechAhb7804r-lm-v3 Version-
XiongmaitechAhb7804r-lms-v3 Firmware Version4.02.r11.nat.onvifc.20171019
   XiongmaitechAhb7804r-lms-v3 Version-
XiongmaitechAhb7008f8-g-v4 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008f8-g-v4 Version-
XiongmaitechAhb7008f4-g-v4 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008f4-g-v4 Version-
XiongmaitechAhb7008f2-g-v4 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008f2-g-v4 Version-
XiongmaitechAhb7032f4-lm-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7032f4-lm-v3 Version-
XiongmaitechAhb7032f2-lm-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7032f2-lm-v3 Version-
XiongmaitechAhb7032f8-gs-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7032f8-gs-v3 Version-
XiongmaitechAhb7032f4-gs-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7032f4-gs-v3 Version-
XiongmaitechAhb7032f2-gs-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7032f2-gs-v3 Version-
XiongmaitechAhb7016t-lme-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7016t-lme-v3 Version-
XiongmaitechAhb7008t-lme-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7008t-lme-v3 Version-
XiongmaitechAhb7004t-lme-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7004t-lme-v3 Version-
XiongmaitechAhb7808r-mh-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7808r-mh-v3 Version-
XiongmaitechAhb7804r-mh-v3 Firmware Version4.02.r11.7601
   XiongmaitechAhb7804r-mh-v3 Version-
XiongmaitechIpg-83h40af Firmware Version-
   XiongmaitechIpg-83h40af Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.04% 0.831
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.