Denial of Service Vulnerability in Sricam IP CCTV Cameras by Sricam
CVE-2019-6973
Key Information:
Badges
What is CVE-2019-6973?
Sricam IP CCTV cameras are susceptible to denial of service attacks due to improper handling of incomplete HTTP requests. The web server, utilizing gSOAP 2.8.x, employs an iterative queueing method which lacks the necessary threading support, resulting in a slow response to requests. Attackers can exploit this weakness by flooding the server with multiple incomplete HTTP requests, leading to potential service unavailability and disruption of surveillance operations.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
13% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
