CVE-2019-3948 EXPLOIT
7.5
HIGH · CVSS 3.0 · EPSS 25% (pctl 98)
Patch early
A public exploit exists.
Description
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.
Scoring
| CVSS | 7.5 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 25.02% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-07-29 |
| Last modified | 2026-06-17 |
Affected (13)
| Vendor | Product |
|---|---|
| amcrest | ip2m-841b |
| amcrest | ip2m-841b firmware |
| dahua | dh-ipc-hx863x |
| dahua | dh-ipc-hx883x |
| dahua | dh-sd4xxxxx |
| dahua | dh-sd5xxxxx |
| dahua | dh-sd6xxxxx |
| dahua | ipc-hx4x3x |
| dahua | ipc-hx5x3x |
| dahua | ipc-xxbxx |
| dahua | nvr2xxx-4ks2 |
| dahua | nvr4xxx-4ks2 |
| dahua | nvr5xxx-4ks2 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming | 2019-07-30 |
References
- http://packetstormsecurity.com/files/153813/Amcrest-Cameras-2.520.AC00.18.R-Unauthenticated-Audio-Streaming.html
- https://us.dahuasecurity.com/wp-content/uploads/2019/08/Cybersecurity_2019-08-02.pdf
- https://www.dahuasecurity.com/support/cybersecurity/details/627?us
- https://www.tenable.com/security/research/tra-2019-36
- http://packetstormsecurity.com/files/153813/Amcrest-Cameras-2.520.AC00.18.R-Unauthenticated-Audio-Streaming.html
- https://us.dahuasecurity.com/wp-content/uploads/2019/08/Cybersecurity_2019-08-02.pdf
- https://www.dahuasecurity.com/support/cybersecurity/details/627?us
- https://www.tenable.com/security/research/tra-2019-36
→ the Explorer · watch your stack · NVD