peter bassill · operator
$ cve CVE-2020-24918 JSON

CVE-2020-24918

9.8
CRITICAL · CVSS 3.1 · EPSS 4.4% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to send a crafted RTSP request, with a long digest authentication header, to execute arbitrary code in parse_authentication_header() in libamprotocol-rtsp.so.1 in rtsp_svc (or cause a crash). This allows remote takeover of a Furbo Dog Camera, for example. NOTE: The vendor states that the RTSP library is used for DEMO only, using it in product is a customer's behavior. Ambarella has emphasized that RTSP is DEMO only library, should NOT be used in product in our document. Because Ambarella's SDK is proprietary, we didn't publish our SDK source code in public network.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.36% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2021-04-30
Last modified2026-06-17

Affected (1)

VendorProduct
ambarellaoryx rtsp server

References

→ the Explorer  ·  watch your stack  ·  NVD