D-Link DCS-8300LHV2 RTSP ValidateAuthorizationHeader Nonce Stack-Based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-51624
8.8HIGH
Summary
A vulnerability exists in D-Link DCS-8300LHV2 IP cameras where inadequate validation of the Authorization header by the RTSP server leads to a stack-based buffer overflow. This flaw, which occurs when the server, listening on TCP port 554, fails to check the length of user-supplied data before it is copied to a fixed-length buffer, allows network-adjacent attackers to execute arbitrary code without authentication. The executed code runs in the context of the root user, posing significant security risks to affected installations.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published