PT-2021-20194 · Geutebrück+1 · Geutebrück Camera Devices+1
Ibrahim Ayadhi
+1
·
Published
2021-09-13
·
Updated
2021-09-27
·
CVE-2021-33547
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UDP Technology camera devices (affected versions not specified)
Geutebrück camera devices (affected versions not specified)
Description
The issue is related to a stack-based buffer overflow condition in the
profile parameter. This may allow an attacker to remotely execute arbitrary code. Multiple camera devices from various vendors, including UDP Technology and Geutebrück, are affected.Recommendations
For UDP Technology camera devices, restrict access to the
profile parameter to minimize the risk of exploitation.
For Geutebrück camera devices, avoid using the profile parameter in affected API endpoints until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geutebrück Camera Devices
Udp Technology Camera Devices