The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.

Project Subscriptions

Vendors Products
Amcrest Subscribe
Ip2m-841b Subscribe
Ip2m-841b Firmware Subscribe
Dh-ipc-hx863x Subscribe
Dh-ipc-hx883x Subscribe
Dh-sd4xxxxx Subscribe
Dh-sd5xxxxx Subscribe
Dh-sd6xxxxx Subscribe
Ipc-hx4x3x Subscribe
Ipc-hx5x3x Subscribe
Ipc-xxbxx Subscribe
Nvr2xxx-4ks2 Subscribe
Nvr4xxx-4ks2 Subscribe
Nvr5xxx-4ks2 Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-04T19:26:27.619Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-3948

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-29T22:15:12.253

Modified: 2024-11-21T04:42:55.520

Link: CVE-2019-3948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses