packetstormsecurity.com
http://packetstormsecurity.com/files/159597/HiSilicon-Video-Encoder-Command-Injection.html CVE-2020-24217
CRITICAL
szuray iptv\/h.264_video_encoder_firmware Missing Authentication for Critical Function
Record summary
CVE-2020-24217 has a selected CVSS score of 9.8 (critical); EIP currently links 2 catalogued exploits.
Description
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 6, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
iptv\/h.264_video_encoder_firmwareBrowse szuray / iptv\/h.264_video_encoder_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
2Catalogued exploits
ExploitDBHiSilicon Video Encoders - RCE via unauthenticated command injectionExploitDB exploitby Alexei KojenovNot analyzed1 file
ExploitDBHiSilicon video encoders - RCE via unauthenticated upload of malicious firmwareExploitDB exploitby Alexei KojenovNot analyzed1 file
References
5packetstormsecurity.com
http://packetstormsecurity.com/files/159599/HiSilicon-Video-Encoder-Malicious-Firmware-Code-Execution.html kojenov.com
https://kojenov.com/2020-09-15-hisilicon-encoder-vulnerabilities nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-24217 kb.cert.org
https://www.kb.cert.org/vuls/id/896979