Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binary executable '/usr/sbin/DM' that listens on port TCP 6666. The service is vulnerable to a stack buffer overflow. It is worth noting that this service does not require any authentication.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://ioactive.com/verint-ptz-cameras-multiple-vulnerabilities/ | third party advisory |
https://ioac.tv/2Nbc40h | third party advisory exploit |