Unauthenticated Audio Streaming Vulnerability in Amcrest and Dahua IP Cameras
CVE-2019-3948
7.5HIGH
What is CVE-2019-3948?
This vulnerability allows an unauthenticated remote attacker to connect to the HTTP endpoint /videotalk on various models of Amcrest and Dahua IP cameras, potentially enabling them to listen in on audio captured by the device. Affected models do not require authentication, leading to serious privacy and security concerns for users. Proper security measures should be implemented to mitigate unauthorized access.
Affected Version(s)
Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R
Dahua DH-SD4XXXXX V2.623.0000000.7.R
Dahua DH-SD5XXXXX V2.623.0000000.1.R
References
EPSS Score
44% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved