CVE-2015-4409
medium
CVSS v3
6.5
CVSS v2
6.8
VIR risk
6.5
Description
Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request, aka the SDK issue.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.hikvision.com/En/Press-Release-details_435_i1023.html
References
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.