Vulnerability Description
badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody can access the web management page of the camera. and must manually restart the device or re-power it. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hanwhavision | Ano-L6012R Firmware | < 1.41.16 |
| Hanwhavision | Ano-L6012R | - |
| Hanwhavision | Ano-L6022R Firmware | < 1.41.16 |
| Hanwhavision | Ano-L6022R | - |
| Hanwhavision | Anv-L6012R Firmware | < 1.41.16 |
| Hanwhavision | Anv-L6012R | - |
| Hanwhavision | Ano-L6082R Firmware | < 1.41.16 |
| Hanwhavision | Ano-L6082R | - |
| Hanwhavision | Ane-L6012R Firmware | < 1.41.16 |
| Hanwhavision | Ane-L6012R | - |
| Hanwhavision | Anv-L6082R Firmware | < 1.41.16 |
| Hanwhavision | Anv-L6082R | - |
| Hanwhavision | Ano-L7082R Firmware | < 1.41.16 |
| Hanwhavision | Ano-L7082R | - |
| Hanwhavision | Ane-L7012R Firmware | < 1.41.16 |
| Hanwhavision | Ane-L7012R | - |
| Hanwhavision | Anv-L7082R Firmware | < 1.41.16 |
| Hanwhavision | Anv-L7082R | - |
| Hanwhavision | Ano-L7012R Firmware | < 1.41.16 |
| Hanwhavision | Ano-L7012R | - |
Related Weaknesses (CWE)
References
- https://www.hanwhavision.com/wp-content/uploads/2024/06/Camera-Vulnerability-RepVendor Advisory
- https://www.hanwhavision.com/wp-content/uploads/2024/06/Camera-Vulnerability-RepVendor Advisory
FAQ
What is CVE-2023-5038?
CVE-2023-5038 is a vulnerability with a CVSS score of 7.5 (HIGH). badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody can access the web management page of the camera. a...
How severe is CVE-2023-5038?
CVE-2023-5038 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5038?
Check the references section above for vendor advisories and patch information. Affected products include: Hanwhavision Ano-L6012R Firmware, Hanwhavision Ano-L6012R, Hanwhavision Ano-L6022R Firmware, Hanwhavision Ano-L6022R, Hanwhavision Anv-L6012R Firmware.