provideoinstruments CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

provideoinstruments vulnerability overview

Aggregates CVE and security vulnerability intelligence across all provideoinstruments-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk buffer overflow and vendor risk command injection, with potential vendor impact application crash across vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2020-24217 An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution. [email protected] 9.8 31.94% 2020-10-06 2024-11-21
CVE-2020-24216 An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is still available via its default name such as /0. Unauthenticated attackers can view video streams that are meant to be private. [email protected] 7.5 0.71% 2020-10-06 2024-11-21
CVE-2020-24215 An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin password), and uploading a custom firmware update, to ultimately achieve arbitrary code execution. [email protected] 9.8 42.18% 2020-10-06 2024-11-21
CVE-2020-24214 An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash. The device will not be able to perform its main purpose of video encoding and streaming for up to a minute, until it automatically reboots. Attackers can send malicious requests once a minute, effectively disabling the device. [email protected] 9.8 35.74% 2020-10-06 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence