A buffer over flow in Xiongmai DVR devices NBD80X16S-KL, NBD80X09S-KL, NBD80X08S-KL, NBD80X09RA-KL, AHB80X04R-MH, AHB80X04R-MH-V2, AHB80X04-R-MH-V3, AHB80N16T-GS, AHB80N32F4-LME, and NBD90S0VT-QW allows attackers to cause a Denial of Service (DoS) via a crafted RSTP request.
References
Link | Resource |
---|---|
https://blog.ret2.me/post/2022-01-26-exploiting-xiongmai-dvrs/ | Exploit Third Party Advisory |
https://www.xiongmaitech.com/en/index.php/service/notice_info/51/2 | Vendor Advisory |
https://blog.ret2.me/post/2022-01-26-exploiting-xiongmai-dvrs/ | Exploit Third Party Advisory |
https://www.xiongmaitech.com/en/index.php/service/notice_info/51/2 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
History
21 Nov 2024, 06:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.ret2.me/post/2022-01-26-exploiting-xiongmai-dvrs/ - Exploit, Third Party Advisory | |
References | () https://www.xiongmaitech.com/en/index.php/service/notice_info/51/2 - Vendor Advisory |
04 Apr 2022, 20:40
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:xiongmaitech:ahb80n16t-gs_firmware:4.03.r11.7601.nat.onvifc.20211223:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb80x04r-mh:-:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb80x04-r-mh-v3:-:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb80x04r-mh-v2:-:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:nbd80x16s-kl:-:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:nbd80x09s-kl:-:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:ahb80x04r-mh-v2_firmware:4.03.r11.nat.dss.onvifc.20210729:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:nbd90s0vt-qw:-:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:nbd80x16s-kl_firmware:4.03.r11.nat.dss.onvifc.20210727:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb80n32f4-lme:-:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:nbd80x09s-kl_firmware:4.03.r11.nat.dss.onvifc.20210727:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:ahb80x04-r-mh-v3_firmware:4.03.r11.nat.dss.onvifc.20210729:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb80n16t-gs:-:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:ahb80x04r-mh_firmware:4.03.r11.nat.dss.onvifc.20210729:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:nbd80x08s-kl:-:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:nbd80x08s-kl_firmware:4.03.r11.nat.dss.onvifc.20210727:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:nbd80x09ra-kl:-:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:ahb80n32f4-lme_firmware:4.03.r11.7601.nat.onvifc.20211228:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:nbd80x09ra-kl_firmware:4.03.r11.nat.dss.onvifc.20210727:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:nbd90s0vt-qw_firmware:4.03.r11.713g.nat.onvifc.2021:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 4.6
v3 : 7.8 |
CWE | CWE-120 | |
References | (MISC) https://www.xiongmaitech.com/en/index.php/service/notice_info/51/2 - Vendor Advisory | |
References | (MISC) https://blog.ret2.me/post/2022-01-26-exploiting-xiongmai-dvrs/ - Exploit, Third Party Advisory |
28 Mar 2022, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-03-28 01:15
Updated : 2024-11-21 06:53
NVD link : CVE-2022-26259
Mitre link : CVE-2022-26259
CVE.ORG link : CVE-2022-26259
JSON object : View
Products Affected
xiongmaitech
- nbd80x08s-kl
- ahb80n16t-gs
- ahb80x04-r-mh-v3
- ahb80n32f4-lme
- ahb80n16t-gs_firmware
- ahb80x04r-mh-v2_firmware
- ahb80x04r-mh-v2
- nbd80x09ra-kl
- nbd90s0vt-qw_firmware
- ahb80x04r-mh
- nbd80x08s-kl_firmware
- nbd80x09s-kl
- ahb80x04r-mh_firmware
- nbd80x09s-kl_firmware
- nbd90s0vt-qw
- nbd80x09ra-kl_firmware
- ahb80x04-r-mh-v3_firmware
- ahb80n32f4-lme_firmware
- nbd80x16s-kl_firmware
- nbd80x16s-kl
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')