Impact
A heap buffer overflow exists in a subset of Hikvision DS-2CD and DS-2DE camera models. The flaw can be triggered by sending specially crafted packets, resulting in device malfunction. The vulnerability falls under CWE‑122 and does not grant privilege escalation or data exfiltration, but it compromises the reliability of the affected devices.
Affected Systems
The affected products are Hikvision DS-2CD series cameras and Hikvision DS-2DE series cameras. No specific firmware or hardware revisions are listed, so the risk applies to any camera that falls under these series until a patch is applied.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity, and the EPSS score of less than 1% suggests a low yet non‑zero probability of exploitation. The flaw is not currently listed in the CISA KEV catalog. The likely attack vector is remote, unauthenticated network traffic that delivers the malicious packet to the camera. Because no user interaction or authentication is required, an attacker could cause repeated restarts or permanent malfunctions, impacting availability but not confidentiality or integrity.
OpenCVE Enrichment