PT-2021-20194 · Geutebrück+1 · Geutebrück Camera Devices+1

Ibrahim Ayadhi

+1

·

Published

2021-09-13

·

Updated

2021-09-27

·

CVE-2021-33547

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UDP Technology camera devices (affected versions not specified) Geutebrück camera devices (affected versions not specified)
Description The issue is related to a stack-based buffer overflow condition in the profile parameter. This may allow an attacker to remotely execute arbitrary code. Multiple camera devices from various vendors, including UDP Technology and Geutebrück, are affected.
Recommendations For UDP Technology camera devices, restrict access to the profile parameter to minimize the risk of exploitation. For Geutebrück camera devices, avoid using the profile parameter in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33547

Affected Products

Geutebrück Camera Devices
Udp Technology Camera Devices