Vulnerability Description
An issue was discovered on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras. An attacker on the same local network as the camera can craft a message with a size field larger than 0x80000000 and send it to the camera, related to an integer overflow or use of a negative number. This then crashes the camera for about 120 seconds.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xiongmaitech | Besder Ip20H1 Firmware | 4.02.r12.00035520.12012.047500.00200 |
| Xiongmaitech | Besder Ip20H1 | - |
Related Weaknesses (CWE)
References
- http://blog.0x42424242.in/2019/04/besder-investigative-journey-part-1_24.htmlExploitThird Party Advisory
- https://www.youtube.com/watch?v=SnyPJtDDMFQExploitThird Party Advisory
- http://blog.0x42424242.in/2019/04/besder-investigative-journey-part-1_24.htmlExploitThird Party Advisory
- https://www.youtube.com/watch?v=SnyPJtDDMFQExploitThird Party Advisory
FAQ
What is CVE-2019-11878?
CVE-2019-11878 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue was discovered on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras. An attacker on the same local network as the camera can craft a message with a size field larger than 0...
How severe is CVE-2019-11878?
CVE-2019-11878 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11878?
Check the references section above for vendor advisories and patch information. Affected products include: Xiongmaitech Besder Ip20H1 Firmware, Xiongmaitech Besder Ip20H1.