CVE-2019-3948 describes an authentication bypass vulnerability in various Amcrest and Dahua IP cameras and NVRs. Specifically, these devices do not require authentication to access the /videotalk HTTP endpoint. This allows an unauthenticated, remote attacker to connect to this endpoint and potentially listen to the audio captured by the device. The vulnerability has a CVSS v3 score of 7.5 (High), indicating a critical risk due to its network-based attack vector and low attack complexity, leading to a high impact on confidentiality. While not listed in CISA's KEV catalog, an exploit module for Amcrest cameras is available on ExploitDB. Despite the public exploit, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.520.ac00.18.rCPE matchmatch criteria | cpe:2.3:o:amcrest:ip2m-841b_firmware:2.520.ac00.18.r:*:*:*:*:*:*:* | ||
< 2018-05-18CPE matchmatch criteria | cpe:2.3:o:dahua:dh-ipc-hx863x:*:*:*:*:*:*:*:* | ||
< 2018-05-18CPE matchmatch criteria | cpe:2.3:o:dahua:dh-ipc-hx883x:*:*:*:*:*:*:*:* | ||
< 2018-05-18CPE matchmatch criteria | cpe:2.3:o:dahua:dh-sd4xxxxx:*:*:*:*:*:*:*:* | ||
< 2018-05-18CPE matchmatch criteria | cpe:2.3:o:dahua:dh-sd5xxxxx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Amcrest IP Camera Multiple Vulnerabilities
Jul 29, 2019Amcrest IP Camera Multiple Vulnerabilities
Jul 29, 2019Amcrest IP Camera Multiple Vulnerabilities
Jul 29, 2019Amcrest IP Camera Multiple Vulnerabilities
Jul 29, 2019Amcrest IP Camera Multiple Vulnerabilities
Jul 29, 2019Amcrest IP Camera Multiple Vulnerabilities
Jul 29, 2019