PT-2017-3410 · Xiongmai Technology · Netsurveillance Web+2

Clinton Mielke

·

Published

2017-12-07

·

Updated

2023-03-29

·

CVE-2017-16725

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xiongmai Technology IP Cameras and DVRs (affected versions not specified)
Description A Stack-based Buffer Overflow issue has been discovered, which may allow an attacker to execute code remotely or crash the device. After rebooting, the device restores itself to a more vulnerable state in which Telnet is accessible. The vulnerability is related to the NetSurveillance Web interface.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2018-00198
CVE-2017-16725

Affected Products

Netsurveillance Web
Xiongmai Dvrs
Xiongmai Ip Cameras