PT-2014-2887 · Avtech · Avtech Avn801 Dvr

Anibal Sacco

·

Published

2014-03-03

·

Updated

2014-03-04

·

CVE-2013-4980

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions AVTECH AVN801 DVR versions 1017-1003-1009-1003 and earlier
Description The issue is related to a buffer overflow in the RTSP Packet Handler, which can be triggered by a long string in the URI in an RTSP SETUP request, such as "/rtsp/setup". This can cause a denial of service, resulting in a device crash, and potentially allow the execution of arbitrary code.
Recommendations For AVTECH AVN801 DVR versions 1017-1003-1009-1003 and earlier, update the firmware to a version later than 1017-1003-1009-1003 to resolve the issue. As a temporary workaround, consider restricting access to the RTSP SETUP request to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4980

Affected Products

Avtech Avn801 Dvr