vendor:
HiSilicon Video Encoders
by:
Alexei Kojenov
9.8
CVSS
CRITICAL
Command Injection
78
CWE
Product Name: HiSilicon Video Encoders
Affected Version From: Vendor-specific
Affected Version To: Vendor-specific
Patch Exists: YES
Related CWE: CVE-2020-24217
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
HiSilicon video encoders – RCE via unauthenticated command injection
A vulnerability in HiSilicon video encoders allows an unauthenticated attacker to execute arbitrary commands on the device. This vulnerability affects multiple vendors, including URayTech, J-Tech Digital, and ProVideoInstruments. The vulnerability is caused by insufficient input validation of user-supplied data, which allows an attacker to inject arbitrary commands into the device.
Mitigation:
Vendors should ensure that user-supplied data is properly validated before being used in system commands. Additionally, vendors should ensure that all user-supplied data is properly sanitized and encoded to prevent malicious input.