Impact
A stack-based buffer overflow was discovered in certain Hikvision DS-2CD and DS-2DE series cameras. The vulnerability allows an attacker with authenticated access to send specially crafted packets, triggering a stack corruption that can cause the camera to malfunction or experience a denial of service. The flaw is a classic stack buffer overflow (CWE-121). This results in loss of availability for the affected device.
Affected Systems
Hikvision DS-2CD Series and DS-2DE Series cameras are impacted. No detailed firmware revisions are supplied, so any device falling under these series that has not applied the latest firmware may be vulnerable. All models within these series that are still running the affected firmware are susceptible.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while the EPSS score of less than 1% suggests a low current exploitation likelihood. The vulnerability requires authenticated access, implying the attack vector is likely limited to users inside the camera's local network or with credentials. The flaw is not listed in CISA's KEV catalog, indicating it has not yet been widely seen in the wild. Nevertheless, any authenticated attacker can trigger the overflow and disrupt the device's operation.
OpenCVE Enrichment