vendor:
IP2M-841
by:
Jacob Baines
7.5
CVSS
HIGH
Unauthenticated Audio Streaming
284
CWE
Product Name: IP2M-841
Affected Version From: V2.520.AC00.18.R
Affected Version To: V2.420.AC00.18.R
Patch Exists: YES
Related CWE: CVE-2019-3948
CPE: h:amcrest:ip2m-841
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8558/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8559/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8544/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8551/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8563/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8506/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8518/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8523/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8524/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8535/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8536/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-11070/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-8375/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-6251/
Other Scripts:
N/A
Platforms Tested: Tested on Amcrest IP2M-841 but known to affect other Dahua devices.
2019
Unauthenticated Audio Streaming from Amcrest Camera
An unauthenticated attacker can access audio streaming from Amcrest Camera by sending a specially crafted HTTP request to the camera. This vulnerability affects Amcrest IP2M-841 but is known to affect other Dahua devices. The response is a series of 4 byte chunks. The first two bytes are the length of the audio data, the second two bytes are the audio data itself.
Mitigation:
Upgrade to the latest version of the firmware to mitigate this vulnerability.