6.8

CVE-2020-5736

Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amcrest1080-lite 8ch Firmware Version-
   Amcrest1080-lite 8ch Version-
AmcrestAmdv10814-h5 Firmware Version-
   AmcrestAmdv10814-h5 Version-
AmcrestIpm-721 Firmware Version < v2.420.ac00.18.r.20200217
   AmcrestIpm-721 Version-
AmcrestIp2m-841 Firmware Version < v2.420.ac00.18.r.20200217
   AmcrestIp2m-841 Version-
AmcrestIp2m-841-v3 Firmware Version < v2.800.0000000.6.r.200314
   AmcrestIp2m-841-v3 Version-
AmcrestIp2m-853ew Firmware Version < v2.623.00ac004.0.r.200316
   AmcrestIp2m-853ew Version-
AmcrestIp2m-858w Firmware Version < v2.623.00ac004.0.r.200316
   AmcrestIp2m-858w Version-
AmcrestIp2m-866w Firmware Version < v2.623.00ac004.0.r.200316
   AmcrestIp2m-866w Version-
AmcrestIp2m-866ew Firmware Version < v2.623.00ac004.0.r.200316
   AmcrestIp2m-866ew Version-
AmcrestIp4m-1053ew Firmware Version < v2.623.00ac004.0.r.200316
   AmcrestIp4m-1053ew Version-
AmcrestIp8m-2454ew Firmware Version < v2.622.00ac000.0.r.200320
   AmcrestIp8m-2454ew Version-
AmcrestIp8m-2493eb Firmware Version < v2.622.00ac000.0.r.200320
   AmcrestIp8m-2493eb Version-
AmcrestIp8m-2496eb Firmware Version < v2.622.00ac000.0.r.200320
   AmcrestIp8m-2496eb Version-
AmcrestIp8m-2597e Firmware Version < v2.800.00ac000.0.r.200330
   AmcrestIp8m-2597e Version-
AmcrestIp8m-mb2546ew Firmware Version < v2.622.00ac000.0.r.200320
   AmcrestIp8m-mb2546ew Version-
AmcrestIp8m-mt2544ew Firmware Version < v2.622.00ac000.0.r.200320
   AmcrestIp8m-mt2544ew Version-
AmcrestIp8m-t2499ew Firmware Version < v2.622.00ac000.0.r.200320
   AmcrestIp8m-t2499ew Version-
AmcrestIpm-hx1 Firmware Version < v2.420.ac00.18.r.20200217
   AmcrestIpm-hx1 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.73% 0.717
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 6.8 8 6.9
AV:N/AC:L/Au:S/C:N/I:N/A:C
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.