Vulnerability Description
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Szuray | Iptv\/H.264 Video Encoder Firmware | <= 1.97 |
| Szuray | Uaioe264-1U | - |
| Szuray | Uce264-1-Mini | - |
| Szuray | Uce264-1Wb-Mini | - |
| Szuray | Uce264-4-1U | - |
| Szuray | Uce264-8-1U | - |
| Szuray | Uhae264-16 | - |
| Szuray | Uhce264-1 | - |
| Szuray | Uhce264-16P32 | - |
| Szuray | Uhce264-1P2 | - |
| Szuray | Uhce264-1P2-1U | - |
| Szuray | Uhce264-1S | - |
| Szuray | Uhce264-1W | - |
| Szuray | Uhce264-1Ws | - |
| Szuray | Uhce264-4P8 | - |
| Szuray | Uhe264-1-4K | - |
| Szuray | Uhe264-16 | - |
| Szuray | Uhe264-16L-3U | - |
| Szuray | Uhe264-16S-2U | - |
| Szuray | Uhe264-1L | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/159595/HiSilicon-Video-Encoder-1.97-File-DiExploitThird Party AdvisoryVDB Entry
- https://kojenov.com/2020-09-15-hisilicon-encoder-vulnerabilities/ExploitThird Party Advisory
- https://www.kb.cert.org/vuls/id/896979Third Party AdvisoryUS Government Resource
- http://packetstormsecurity.com/files/159595/HiSilicon-Video-Encoder-1.97-File-DiExploitThird Party AdvisoryVDB Entry
- https://kojenov.com/2020-09-15-hisilicon-encoder-vulnerabilities/ExploitThird Party Advisory
- https://www.kb.cert.org/vuls/id/896979Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-24219?
CVE-2020-24219 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming fl...
How severe is CVE-2020-24219?
CVE-2020-24219 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24219?
Check the references section above for vendor advisories and patch information. Affected products include: Szuray Iptv\/H.264 Video Encoder Firmware, Szuray Uaioe264-1U, Szuray Uce264-1-Mini, Szuray Uce264-1Wb-Mini, Szuray Uce264-4-1U.