ID

VAR-202008-0808


CVE

CVE-2020-3507


TITLE

Cisco Video Surveillance 8000  series  IP  Camera input verification vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2020-010680

DESCRIPTION

Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabilities are due to missing checks when the IP cameras process a Cisco Discovery Protocol packet. An attacker could exploit these vulnerabilities by sending a malicious Cisco Discovery Protocol packet to the targeted IP camera. A successful exploit could allow the attacker to execute code on the affected IP camera or cause it to reload unexpectedly, resulting in a denial of service (DoS) condition. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit these vulnerabilities, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent)

Trust: 2.16

sources: NVD: CVE-2020-3507 // JVNDB: JVNDB-2020-010680 // CNVD: CNVD-2020-52367

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

category:['camera device']sub_category:IP camera

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2020-52367

AFFECTED PRODUCTS

vendor:ciscomodel:8000p ip camerascope:eqversion:1.0.9-1

Trust: 1.0

vendor:ciscomodel:8020 ip camerascope:eqversion:1.0.9-1

Trust: 1.0

vendor:ciscomodel:8070 ip camerascope:eqversion:1.0.9-1

Trust: 1.0

vendor:ciscomodel:8620 ip camerascope:eqversion:1.0.9-1

Trust: 1.0

vendor:ciscomodel:8400 ip camerascope:eqversion:1.0.9-1

Trust: 1.0

vendor:ciscomodel:8030 ip camerascope:eqversion:1.0.9-1

Trust: 1.0

vendor:ciscomodel:8930 speed dome ip camerascope:eqversion:1.0.9-1

Trust: 1.0

vendor:ciscomodel:8630 ip camerascope:eqversion:1.0.9-1

Trust: 1.0

vendor:シスコシステムズmodel:cisco video surveillance 8000p ip カメラscope: - version: -

Trust: 0.8

vendor:シスコシステムズmodel:cisco video surveillance 8020 ip カメラscope: - version: -

Trust: 0.8

vendor:シスコシステムズmodel:cisco video surveillance 8030 ip カメラscope: - version: -

Trust: 0.8

vendor:シスコシステムズmodel:cisco video surveillance 8070 ip カメラscope: - version: -

Trust: 0.8

vendor:シスコシステムズmodel:cisco video surveillance 8400 ip カメラscope: - version: -

Trust: 0.8

vendor:シスコシステムズmodel:cisco video surveillance 8620 ip カメラscope: - version: -

Trust: 0.8

vendor:シスコシステムズmodel:cisco video surveillance 8630 ip カメラscope: - version: -

Trust: 0.8

vendor:シスコシステムズmodel:cisco video surveillance 8930 speed dome ip カメラscope: - version: -

Trust: 0.8

vendor:ciscomodel:video surveillance series ip camerasscope:eqversion:8000<1.0.9-4

Trust: 0.6

sources: CNVD: CNVD-2020-52367 // JVNDB: JVNDB-2020-010680 // NVD: CVE-2020-3507

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-3507
value: HIGH

Trust: 1.0

ykramarz@cisco.com: CVE-2020-3507
value: HIGH

Trust: 1.0

NVD: CVE-2020-3507
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-52367
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202008-958
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-3507
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2020-52367
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-3507
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 2.0

NVD: CVE-2020-3507
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-52367 // JVNDB: JVNDB-2020-010680 // CNNVD: CNNVD-202008-958 // NVD: CVE-2020-3507 // NVD: CVE-2020-3507

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.0

problemtype:Incorrect input confirmation (CWE-20) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-010680 // NVD: CVE-2020-3507

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202008-958

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-202008-958

PATCH

title:cisco-sa-ipcameras-rce-dos-uPyJYxN3url:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipcameras-rce-dos-uPyJYxN3

Trust: 0.8

title:Patch for Cisco Video Surveillance 8000 Series IP Cameras remote code execution vulnerability (CNVD-2020-52367)url:https://www.cnvd.org.cn/patchInfo/show/234253

Trust: 0.6

title:Cisco Video Surveillance 8000 Series IP Cameras Enter the fix for the verification error vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=126754

Trust: 0.6

sources: CNVD: CNVD-2020-52367 // JVNDB: JVNDB-2020-010680 // CNNVD: CNNVD-202008-958

EXTERNAL IDS

db:NVDid:CVE-2020-3507

Trust: 3.1

db:JVNDBid:JVNDB-2020-010680

Trust: 0.8

db:CNVDid:CNVD-2020-52367

Trust: 0.6

db:NSFOCUSid:48668

Trust: 0.6

db:AUSCERTid:ESB-2020.2854

Trust: 0.6

db:CNNVDid:CNNVD-202008-958

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2020-52367 // JVNDB: JVNDB-2020-010680 // CNNVD: CNNVD-202008-958 // NVD: CVE-2020-3507

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-ipcameras-rce-dos-upyjyxn3

Trust: 2.2

url:https://nvd.nist.gov/vuln/detail/cve-2020-3507

Trust: 2.0

url:http://www.nsfocus.net/vulndb/48668

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2020.2854/

Trust: 0.6

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2020-52367 // JVNDB: JVNDB-2020-010680 // CNNVD: CNNVD-202008-958 // NVD: CVE-2020-3507

SOURCES

db:OTHERid: -
db:CNVDid:CNVD-2020-52367
db:JVNDBid:JVNDB-2020-010680
db:CNNVDid:CNNVD-202008-958
db:NVDid:CVE-2020-3507

LAST UPDATE DATE

2025-01-30T21:22:35.261000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-52367date:2020-09-16T00:00:00
db:JVNDBid:JVNDB-2020-010680date:2021-02-01T07:40:00
db:CNNVDid:CNNVD-202008-958date:2021-01-05T00:00:00
db:NVDid:CVE-2020-3507date:2024-11-21T05:31:12.853

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-52367date:2020-09-16T00:00:00
db:JVNDBid:JVNDB-2020-010680date:2021-02-01T00:00:00
db:CNNVDid:CNNVD-202008-958date:2020-08-19T00:00:00
db:NVDid:CVE-2020-3507date:2020-08-26T17:15:14.490