peter bassill · operator
$ cve CVE-2019-6973 JSON

CVE-2019-6973 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 13.8% (pctl 96)

Patch early

A public exploit exists.

Description

Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS13.78% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2019-03-21
Last modified2026-06-17

Affected (16)

VendorProduct
geniviagsoap
sricamnvs001
sricamsh016
sricamsh024
sricamsh026
sricamsh027
sricamsp007
sricamsp008
sricamsp009
sricamsp012
sricamsp015
sricamsp017
sricamsp018
sricamsp019
sricamsp020
sricamsp023

Public exploits

SourceTitleDate
exploit-dbSricam gSOAP 2.8 - Denial of Service2019-01-28

References

→ the Explorer  ·  watch your stack  ·  NVD