PT-2024-26443 · Anpviz · Anpviz

Published

2024-05-28

·

Updated

2024-12-05

·

CVE-2024-35342

CVSS v3.1

4.6

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Anpviz products versions 3.2.2.2 and lower
Description The issue allows unauthenticated users to modify or disable camera-related settings, including microphone volume, speaker volume, LED lighting, NTP, motion detection, etc. This affects various Anpviz IP camera models.
Recommendations For Anpviz products versions 3.2.2.2 and lower, consider disabling access to camera settings until a patch is available. Restrict access to the affected camera models to minimize the risk of exploitation. Avoid using the vulnerable camera settings until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-35342

Affected Products

Anpviz