Lucene search

K
cveIcscertCVE-2021-32941
HistoryMay 23, 2022 - 7:16 p.m.

CVE-2021-32941

2022-05-2319:16:07
CWE-787
CWE-121
icscert
web.nvd.nist.gov
77
14
cve-2021-32941
annke n48pbb
network video recorder
buffer overflow
security vulnerability
nvd
unauthorized access

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.005

Percentile

77.2%

Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (root).

Affected configurations

Nvd
Node
annken48pbbMatch-
AND
annken48pbb_firmwareRange<3.4.106
OR
annken48pbb_firmwareMatch3.4.106-
OR
annken48pbb_firmwareMatch3.4.106build_200422
VendorProductVersionCPE
annken48pbb-cpe:2.3:h:annke:n48pbb:-:*:*:*:*:*:*:*
annken48pbb_firmware*cpe:2.3:o:annke:n48pbb_firmware:*:*:*:*:*:*:*:*
annken48pbb_firmware3.4.106cpe:2.3:o:annke:n48pbb_firmware:3.4.106:-:*:*:*:*:*:*
annken48pbb_firmware3.4.106cpe:2.3:o:annke:n48pbb_firmware:3.4.106:build_200422:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "N48PBB (NVR)",
    "vendor": "Annke",
    "versions": [
      {
        "lessThanOrEqual": "V3.4.106 build 200422",
        "status": "affected",
        "version": "All",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.005

Percentile

77.2%

Related for CVE-2021-32941