PT-2024-6580 · Hikvision · Hikvision Ds-7604Ni-K1/4P+1

Published

2024-04-02

·

Updated

2024-10-31

·

CVE-2024-29947

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Hikvision NVRs (affected versions not specified) Hikvision DS-7604NI-K1/4P(B) (affected versions not specified)
Description: The issue is related to a NULL dereference pointer vulnerability. It is caused by insufficient validation of a parameter in a message, allowing an attacker to send specially crafted messages to an affected product. This can cause a process abnormality, potentially leading to a denial of service.
Recommendations: For Hikvision NVRs, consider restricting access to the Message Handler component until a patch is available. For Hikvision DS-7604NI-K1/4P(B), avoid using the vulnerable Message Handler component in the IP camera's microprogram software until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-07725
CVE-2024-29947

Affected Products

Hikvision Ds-7604Ni-K1/4P
Hikvision Nvrs