HiSilicon.Based.Video.Encoders.Remote.Command.Injection
Description
This indicates an attack attempt to exploit one or more vulnerabilities in IPTV/H.264/H.265 video encoders based on HiSilicon hi3520d hardware.
The vulnerability is due to insufficient validation of user supplied inputs when processing HTTP requests. It may allow remote attackers to execute arbitrary system commands and disclose sensitive information within the context of the application.
Affected Products
IPTV/H.264/H.265 video encoders based on HiSilicon hi3520d hardware.
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor:
https://www.oupree.com/News/Security-Advisory-Vulnerability-of-Video-Encoder.html
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |