Skip to content
COOEY

EXPOSURES › CVE-2020-5735

CVE-2020-5735

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-5735 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

Amcrest cameras and NVRs have an unauthenticated remote stack-based buffer overflow on port 37777 that can crash the device and execute code.

An unauthenticated remote attacker can exploit this stack-based buffer overflow to crash the device and execute arbitrary code, posing a severe risk to DIB organizations relying on these devices for physical security or network monitoring. The vulnerability is actively exploited in the wild (KEV), indicating that attackers are already leveraging it, which could lead to device compromise, data exfiltration, or use as a pivot point for further network attacks. DIB organizations must immediately patch these devices or replace them to prevent exploitation and maintain compliance with security requirements.

Shame score — The vulnerability is actively exploited in the wild, allowing unauthenticated remote code execution, which is a severe and avoidable failure for a security-critical device.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Amcrest's vulnerability was unauthenticated and remote, allowing code execution, which is severe but received minimal press coverage in the provided sources, mostly technical databases and CISA adviso
cooey ↗ severe-fallout -0.60
Technical acknowledgment of severe vulnerability without direct vendor praise or condemnation.
"Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code."
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing with no vendor-specific sentiment.
CISA ↗ severe-fallout +0.00
Neutral government advisory page with no vendor-specific sentiment.
CISA ↗ severe-fallout +0.00
Neutral government advisory page with no vendor-specific sentiment.
coverager.com ↗ severe-fallout +0.00
Irrelevant to Amcrest CVE-2020-5735.
app.opencve.io ↗ severe-fallout +0.00
Irrelevant to Amcrest CVE-2020-5735.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.