CVE-2023-5038
badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody can access the web management page of the camera. and must manually restart the device or re-power it. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.40%
- CWE
- CWE-703, CWE-248
- Published
- 2024-06-25
- Last modified
- 2026-03-13
Affected products
- Hanwha Vision Co., Ltd. A-Series, Q-Series, PNM-series Camera
Weakness type
Related vulnerabilities
- CVE-2023-0397 — DoS: Invalid Initialization in le_read_buffer_size_complete
- CVE-2021-3329 — DOS: Incorrect handling of the initial HCI ACL_MTU handshake packet leads to crash of bluetooth host layer
- CVE-2024-39815 — Vonets WiFi Bridges Improper Check or Handling of Exceptional Conditions
- CVE-2021-23859 — Denial of Service and Authentication Bypass Vulnerability in multiple Bosch products
- CVE-2019-5031 — An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, ver
- CVE-2022-22265 — An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary m
- CVE-2024-21525 — All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the
- CVE-2026-20329 — Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities