CVE-2024-42531

Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establish RTSP protocol communictaion, but cannot obtain video or audio data; thus, there is no risk.
Configurations

No configuration.

History

29 Aug 2024, 13:15

Type Values Removed Values Added
Summary
  • (es) Ezviz Internet PT Camera CS-CV246 D15655150 permite que un host no autenticado acceda a su transmisión de video en vivo mediante la creación de un conjunto de paquetes RTSP con un conjunto específico de URL que se pueden usar para redirigir la transmisión de la cámara.
Summary (en) Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. (en) Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a specific set of URLs that can be used to redirect the camera feed. NOTE: the vendor's perspective is that the Anonymous120386 sample code can establish RTSP protocol communictaion, but cannot obtain video or audio data; thus, there is no risk.

23 Aug 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-20

23 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-23 17:15

Updated : 2024-08-29 13:15


NVD link : CVE-2024-42531

Mitre link : CVE-2024-42531

CVE.ORG link : CVE-2024-42531


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation