PT-2022-16819 · Ezviz · Ezviz Cs-Db1C-A0-1E2W2Fr+4

Bitdefender Labs

·

Published

2022-09-15

·

Updated

2022-09-20

·

CVE-2022-2471

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EZVIZ CS-CV248 versions prior to 5.2.3 build 220725 EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428 EZVIZ CS-DB1C-A0-1E2W2FR versions prior to 5.3.0 build 220802 EZVIZ CS-C6N-B0-1G2WF versions prior to 5.3.0 build 220712 EZVIZ CS-C3W-A0-3H4WFRL versions prior to 5.3.5 build 220723
Description A Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component allows a remote attacker to execute remote code on the device. This issue affects various EZVIZ camera models.
Recommendations For EZVIZ CS-CV248 versions prior to 5.2.3 build 220725, update to version 5.2.3 build 220725 or later. For EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428, update to version 5.3.0 build 220428 or later. For EZVIZ CS-DB1C-A0-1E2W2FR versions prior to 5.3.0 build 220802, update to version 5.3.0 build 220802 or later. For EZVIZ CS-C6N-B0-1G2WF versions prior to 5.3.0 build 220712, update to version 5.3.0 build 220712 or later. For EZVIZ CS-C3W-A0-3H4WFRL versions prior to 5.3.5 build 220723, update to version 5.3.5 build 220723 or later.

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-2471

Affected Products

Ezviz Cs-C3W-A0-3H4Wfrl
Ezviz Cs-C6N-A0-1C2Wfr-Mul
Ezviz Cs-C6N-B0-1G2Wf
Ezviz Cs-Cv248
Ezviz Cs-Db1C-A0-1E2W2Fr