Description
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.
Published: 2019-07-29
Score: 7.5 High
EPSS: 45.3% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Amcrest Ip2m-841b Ip2m-841b Firmware
Dahua Dh-ipc-hx863x Dh-ipc-hx883x Dh-sd4xxxxx Dh-sd5xxxxx Dh-sd6xxxxx Ipc-hx4x3x Ipc-hx5x3x Ipc-xxbxx Nvr2xxx-4ks2 Nvr4xxx-4ks2 Nvr5xxx-4ks2
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-04T19:26:27.619Z

Reserved: 2019-01-03T00:00:00.000Z

Link: CVE-2019-3948

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-29T22:15:12.253

Modified: 2024-11-21T04:42:55.520

Link: CVE-2019-3948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses