Amcrest Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Amcrest products.
Products
- Cameras and Network Video Recorder (NVR)1 vulnerability
- IP2M-841B1 vulnerability
- IP2M-841W1 vulnerability
- IPC-IP2M-841B1 vulnerability
- IPC-IP3M-943B1 vulnerability
- IPC-IP3M-943S1 vulnerability
- IPC-IP3M-HX2B1 vulnerability
- IPC-IPM-721S1 vulnerability
- ipm-721s_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-12984MEDIUM | Amcrest IP2M-841B Web Interface webCapsConfig information disclosureA vulnerability classified as problematic has been found in Amcrest IP2M-841B, IP2M-841W, IPC-IP2M-841B, IPC-IP3M-943B, IPC-IP3M-943S, IPC-IP3M-HX2B and IPC-IPM-721S up to 20241211. This affects an unknown part of the file /web_caps/webCapsConfig of the component Web Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did … | CVSS6.9v4.0 | EPSS0.593% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-5735HIGH | Amcrest Cameras and NVR Stack-based Buffer Overflow VulnerabilityAmcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code. | CVSS8.8v3.1 | EPSS36.2% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-8226CRITICAL | Amcrest ipm-721s_firmware Use of Hard-coded CredentialsAmcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the d… CWE-798Jul 3, 2019 | CVSS9.8v3.0 | EPSS3.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |