← Back to browse · API

CVE-2024-0778

Severity
HIGH
CVSS
8.0
EPSS
0.32088
Risk score
43.23
CISA KEV
No
PoC
No
Published
2024-01-22
Modified
2025-05-30
First seen
2026-08-07
Aliases
EUVD-2024-16566, GHSA-82VC-JG89-JQ37
Products
Uniview:ISC 2500-S, Uniview:ISC 2500-S 20210930
Sources
euvd EUVD-2024-16566

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930. Affected by this issue is the function setNatConfig of the file /Interface/DevManage/VM.php. The manipulation of the argument natAddress/natPort/natServerPort leads to os command injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251696. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

References