// For flags

CVE-2021-32941

Annke Network Video Recorder - Stack-based Buffer Overflow

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (root).

Los productos Annke N48PBB (Network Video Recorder) versión 3.4.106 build 200422 y anteriores, son vulnerables a un desbordamiento del búfer en la región stack de la memoria, que permite a un atacante remoto no autorizado ejecutar código arbitrario con los mismos privilegios que el usuario del servidor (root)

*Credits: Andrea Palanca from Nozomi Networks reported this vulnerability to CISA.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-05-13 CVE Reserved
  • 2022-05-23 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-12-27 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-121: Stack-based Buffer Overflow
  • CWE-787: Out-of-bounds Write
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Annke
Search vendor "Annke"
N48pbb Firmware
Search vendor "Annke" for product "N48pbb Firmware"
< 3.4.106
Search vendor "Annke" for product "N48pbb Firmware" and version " < 3.4.106"
-
Affected
in Annke
Search vendor "Annke"
N48pbb
Search vendor "Annke" for product "N48pbb"
--
Safe
Annke
Search vendor "Annke"
N48pbb Firmware
Search vendor "Annke" for product "N48pbb Firmware"
3.4.106
Search vendor "Annke" for product "N48pbb Firmware" and version "3.4.106"
-
Affected
in Annke
Search vendor "Annke"
N48pbb
Search vendor "Annke" for product "N48pbb"
--
Safe
Annke
Search vendor "Annke"
N48pbb Firmware
Search vendor "Annke" for product "N48pbb Firmware"
3.4.106
Search vendor "Annke" for product "N48pbb Firmware" and version "3.4.106"
build_200422
Affected
in Annke
Search vendor "Annke"
N48pbb
Search vendor "Annke" for product "N48pbb"
--
Safe