vendor:
HiSilicon video encoders
by:
Alexei Kojenov
9.8
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: HiSilicon video encoders
Affected Version From: Vendor-specific
Affected Version To: Vendor-specific
Patch Exists: YES
Related CWE: CVE-2020-24214
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
HiSilicon video encoders – unauthenticated RTSP buffer overflow (DoS)
HiSilicon video encoders are vulnerable to an unauthenticated buffer overflow in the RTSP protocol. This vulnerability can be exploited to cause a denial of service (DoS) attack. The exploit involves sending a specially crafted RTSP request with an excessively long CSeq header to the vulnerable device. This will cause the device to crash and become unresponsive.
Mitigation:
Vendors have released patches to address this vulnerability. Users should update their devices to the latest version.