CVE-2023-5038
high-risk
Published 2024-06-25
badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody can access the web management page of the camera. and must manually restart the device or re-power it. The manufacturer has released patch firmware for the flaw, please refer to the manufacturer's report for details and workarounds.
Do I need to act?
-
0.40% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (20)
Ano-L6012R Firmware
Ano-L6022R Firmware
Anv-L6012R Firmware
Ano-L6082R Firmware
Ane-L6012R Firmware
Anv-L6082R Firmware
Ano-L7082R Firmware
Ane-L7012R Firmware
Anv-L7082R Firmware
Ano-L7012R Firmware
Ano-L7022R Firmware
Anv-L7012R Firmware
Pnm-C9022Rv Firmware
Pnm-9000Qb Firmware
Pnm-7002Vd Firmware
Pnm-8082Vt Firmware
Pnm-9002Vq Firmware
Pnm-9022V Firmware
Pnm-9031Rv Firmware
Pnm-9084Qz Firmware
Affected Vendors
References (2)
61
/ 100
high-risk
Severity
26/34 · High
Exploitability
2/34 · Minimal
Exposure
33/34 · Critical