Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wvxm-h79q-qcrm

Опубликовано: 24 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can cause a stack overflow by entering large data into URL parameters, which will result in a system reboot. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can cause a stack overflow by entering large data into URL parameters, which will result in a system reboot. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

EPSS

Процентиль: 64%
0.00475
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-119
CWE-121

Связанные уязвимости

nvd
около 1 года назад

Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can cause a stack overflow by entering large data into URL parameters, which will result in a system reboot. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.

EPSS

Процентиль: 64%
0.00475
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-119
CWE-121