A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a special RTSP over HTTP packet. The vulnerability was found in many cameras using hisilicon's hardware and software, as demonstrated by TENVIS cameras 1.3.3.3, 1.2.7.2, 1.2.1.4, 7.1.20.1.2, and 13.1.1.1.7.2; FDT FD7902 11.3.14.1.3 and 10.3.14.1.3; FOSCAM cameras 3.2.1.1.1_0815 and 3.2.2.2.1_0815; and Dericam cameras V11.3.8.1.12.
References
Link | Resource |
---|---|
https://gist.github.com/vulnfan1337/e95c2dba75ad93a1a325c6ace950eba9 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2019-05-07 09:29
Updated : 2021-07-21 04:39
NVD link : CVE-2019-11560
Mitre link : CVE-2019-11560
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
hisilicon
- hi3516
- hi3516_firmware