HiSilicon.DVR.Devices.Remote.Code.Execution
Description
This indicates an attack attempt to exploit one or more vulnerabilities in HiSilicon DVR devices.
The vulnerability is due to insufficient validation of user supplied inputs when processing HTTP requests. It may allow remote attackers to execute arbitrary system commands and disclose sensitive information within the context of the application.
Affected Products
HiSilicon DVR devices
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Monitor the traffic from that network for any suspicious activity.
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2020-09-14 | 16.922 | |
2019-11-29 | 15.736 | Default_action:pass:drop |
2019-10-23 | 14.709 |