Vulnerability Description
Certain Hanwha products are vulnerable to Denial of Service (DoS). ck vector is: When an empty UDP packet is sent to the listening service, the service thread results in a non-functional service (DoS) via WS Discovery and Hanwha proprietary discovery services. This affects IP Camera ANE-L7012R 1.41.01 and IP Camera XNV-9082R 2.10.02.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hanwhavision | Ane-L6012R Firmware | < 1.41.03 |
| Hanwhavision | Ane-L6012R | - |
| Hanwhavision | Ane-L7012R Firmware | < 1.41.03 |
| Hanwhavision | Ane-L7012R | - |
| Hanwhavision | Ano-L6012R Firmware | < 1.41.03 |
| Hanwhavision | Ano-L6012R | - |
| Hanwhavision | Ano-L6022R Firmware | < 1.41.03 |
| Hanwhavision | Ano-L6022R | - |
| Hanwhavision | Ano-L6082R Firmware | < 1.41.03 |
| Hanwhavision | Ano-L6082R | - |
| Hanwhavision | Ano-L7012R Firmware | < 1.41.03 |
| Hanwhavision | Ano-L7012R | - |
| Hanwhavision | Ano-L7022R Firmware | < 1.41.03 |
| Hanwhavision | Ano-L7022R | - |
| Hanwhavision | Ano-L7082R Firmware | < 1.41.03 |
| Hanwhavision | Ano-L7082R | - |
| Hanwhavision | Anv-L6012R Firmware | < 1.41.03 |
| Hanwhavision | Anv-L6012R | - |
| Hanwhavision | Anv-L6023R Firmware | < 1.41.03 |
| Hanwhavision | Anv-L6023R | - |
References
- https://hanwhavisionamerica.com/download/50042/Vendor Advisory
- https://www.hanwhavision.com/wp-content/uploads/2023/04/Camera-Vulnerability-RepBroken Link
- https://hanwhavisionamerica.com/download/50042/Vendor Advisory
- https://www.hanwhavision.com/wp-content/uploads/2023/04/Camera-Vulnerability-RepBroken Link
FAQ
What is CVE-2023-31994?
CVE-2023-31994 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Certain Hanwha products are vulnerable to Denial of Service (DoS). ck vector is: When an empty UDP packet is sent to the listening service, the service thread results in a non-functional service (DoS)...
How severe is CVE-2023-31994?
CVE-2023-31994 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-31994?
Check the references section above for vendor advisories and patch information. Affected products include: Hanwhavision Ane-L6012R Firmware, Hanwhavision Ane-L6012R, Hanwhavision Ane-L7012R Firmware, Hanwhavision Ane-L7012R, Hanwhavision Ano-L6012R Firmware.