V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-33549
CVE
High

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the ac…

CVSS
7.2
High
EPSS
0.66
p99
Published
2021-01-01
Updated
2021-01-01
Description

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code.

Tags · CWE
CWE-121
Affected products
G-cam_ebc-2110_firmwareG-cam_ebc-2111_firmwareG-cam_ebc-2112_firmwareG-cam_efd-2241_firmwareG-cam_efd-2250_firmwareG-cam_efd-2251_firmwareG-cam_ethc-2230_firmwareG-cam_ethc-2239_firmwareG-cam_ethc-2240_firmwareG-cam_ethc-2249_firmwareG-cam_ewpc-2270_firmwareG-cam_ewpc-2271_firmwareG-cam_ewpc-2275_firmwareG-code_eec-2400_firmwareG-code_een-2010_firmwareG-code_een-2040_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: H
High (H)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.662 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
g-cam_ebc-2110_firmware*Tracked
g-cam_ebc-2111_firmware*Tracked
g-cam_ebc-2112_firmware*Tracked
g-cam_efd-2241_firmware*Tracked
g-cam_efd-2250_firmware*Tracked
g-cam_efd-2251_firmware*Tracked
g-cam_ethc-2230_firmware*Tracked
g-cam_ethc-2239_firmware*Tracked
g-cam_ethc-2240_firmware*Tracked
g-cam_ethc-2249_firmware*Tracked
g-cam_ewpc-2270_firmware*Tracked
g-cam_ewpc-2271_firmware*Tracked
g-cam_ewpc-2275_firmware*Tracked
g-code_eec-2400_firmware*Tracked
g-code_een-2010_firmware*Tracked
g-code_een-2040_firmware*Tracked
Source databases
CVE