CVE-2019-3948
Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.
El Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X y HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X y DH-IPC- HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R y V2.623.0000000.1 .R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R y NVR2XXX-4KS2 no requieren autenticación para acceder al punto final HTTP / videotalk. Una persona remota no autenticada puede conectarse a este punto final y escuchar potencialmente el audio del dispositivo de captura.
Amcrest Cameras version 2.520.AC00.18.R suffers from an authentication bypass vulnerability allowing an attacker to retrieve audio streams.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-03 CVE Reserved
- 2019-07-29 CVE Published
- 2019-07-30 First Exploit
- 2024-08-04 CVE Updated
- 2024-12-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://us.dahuasecurity.com/wp-content/uploads/2019/08/Cybersecurity_2019-08-02.pdf | X_refsource_misc | |
https://www.dahuasecurity.com/support/cybersecurity/details/627?us | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Amcrest Search vendor "Amcrest" | Ip2m-841b Firmware Search vendor "Amcrest" for product "Ip2m-841b Firmware" | 2.520.ac00.18.r Search vendor "Amcrest" for product "Ip2m-841b Firmware" and version "2.520.ac00.18.r" | - |
Affected
| in | Amcrest Search vendor "Amcrest" | Ip2m-841b Search vendor "Amcrest" for product "Ip2m-841b" | - | - |
Safe
|
Dahua Search vendor "Dahua" | Dh-ipc-hx863x Search vendor "Dahua" for product "Dh-ipc-hx863x" | < 2018-05-18 Search vendor "Dahua" for product "Dh-ipc-hx863x" and version " < 2018-05-18" | - |
Affected
| ||||||
Dahua Search vendor "Dahua" | Dh-ipc-hx883x Search vendor "Dahua" for product "Dh-ipc-hx883x" | < 2018-05-18 Search vendor "Dahua" for product "Dh-ipc-hx883x" and version " < 2018-05-18" | - |
Affected
| ||||||
Dahua Search vendor "Dahua" | Dh-sd4xxxxx Search vendor "Dahua" for product "Dh-sd4xxxxx" | < 2018-05-18 Search vendor "Dahua" for product "Dh-sd4xxxxx" and version " < 2018-05-18" | - |
Affected
| ||||||
Dahua Search vendor "Dahua" | Dh-sd5xxxxx Search vendor "Dahua" for product "Dh-sd5xxxxx" | < 2018-05-18 Search vendor "Dahua" for product "Dh-sd5xxxxx" and version " < 2018-05-18" | - |
Affected
| ||||||
Dahua Search vendor "Dahua" | Dh-sd6xxxxx Search vendor "Dahua" for product "Dh-sd6xxxxx" | < 2018-05-18 Search vendor "Dahua" for product "Dh-sd6xxxxx" and version " < 2018-05-18" | - |
Affected
| ||||||
Dahua Search vendor "Dahua" | Ipc-hx4x3x Search vendor "Dahua" for product "Ipc-hx4x3x" | < 2018-05-18 Search vendor "Dahua" for product "Ipc-hx4x3x" and version " < 2018-05-18" | - |
Affected
| ||||||
Dahua Search vendor "Dahua" | Ipc-hx5x3x Search vendor "Dahua" for product "Ipc-hx5x3x" | < 2018-05-18 Search vendor "Dahua" for product "Ipc-hx5x3x" and version " < 2018-05-18" | - |
Affected
| ||||||
Dahua Search vendor "Dahua" | Ipc-xxbxx Search vendor "Dahua" for product "Ipc-xxbxx" | < 2018-05-18 Search vendor "Dahua" for product "Ipc-xxbxx" and version " < 2018-05-18" | - |
Affected
| ||||||
Dahua Search vendor "Dahua" | Nvr2xxx-4ks2 Search vendor "Dahua" for product "Nvr2xxx-4ks2" | < 2018-05-18 Search vendor "Dahua" for product "Nvr2xxx-4ks2" and version " < 2018-05-18" | - |
Affected
| ||||||
Dahua Search vendor "Dahua" | Nvr4xxx-4ks2 Search vendor "Dahua" for product "Nvr4xxx-4ks2" | < 2018-05-18 Search vendor "Dahua" for product "Nvr4xxx-4ks2" and version " < 2018-05-18" | - |
Affected
| ||||||
Dahua Search vendor "Dahua" | Nvr5xxx-4ks2 Search vendor "Dahua" for product "Nvr5xxx-4ks2" | < 2018-05-18 Search vendor "Dahua" for product "Nvr5xxx-4ks2" and version " < 2018-05-18" | - |
Affected
|