CVE-2020-5735 — Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
CVE-2020-5735: Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Amcrest |
| Product | Cameras and Network Video Recorder (NVR) |
| Date added | 2021-11-03 |
| Due date | 2022-05-03 |
| Ransomware campaign use | Unknown |
Description
Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2020-5735
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-5735
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog