Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-12727

Опубликовано: 04 июн. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-streamer binary. The issue can be triggered via malformed RTSP requests that lead to an invalid memory read. To exploit the vulnerability, an attacker must craft an RTSP request with a large number of headers.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:ui:aircam_firmware:3.1.4:*:*:*:*:*:*:*
cpe:2.3:h:ui:aircam:-:*:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00296
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-125

Связанные уязвимости

github
больше 3 лет назад

On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-streamer binary. The issue can be triggered via malformed RTSP requests that lead to an invalid memory read. To exploit the vulnerability, an attacker must craft an RTSP request with a large number of headers.

EPSS

Процентиль: 53%
0.00296
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-125