Impact
The vulnerability allows unauthenticated attackers to read portions of the camera’s memory, potentially exposing sensitive configuration or identification details. This is a classic information disclosure weakness (CWE‑200) that can compromise the confidentiality of the device.
Affected Systems
Affected devices include Hikvision DS-2CD and DS-2DE series cameras. No specific firmware or model version information is provided, so any camera in those series may be vulnerable until confirmation.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. Because the vulnerability is unauthenticated, the likely attack vector is remote, network‑based access to the camera’s exposed interfaces, but no exploit has been reported or listed in CISA’s KEV catalog.
OpenCVE Enrichment