Anjvision YSSD-RTMP-H5
Summary
Multiple critical vulnerabilities have been identified in Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4. Successful exploitation could grant attackers unauthorized access to sensitive information, user accounts, OS-level commands, and full device control.
IFF Assessment
The article details critical vulnerabilities that allow attackers to gain significant control over affected devices, posing a direct threat to security.
Severity
The CVSS score of 9.8 indicates a critical severity, reflecting the potential for an attacker to gain full control over the device, access sensitive information, and execute OS commands due to issues like OS Command Injection and SSRF.
Defender Context
This advisory highlights critical vulnerabilities in industrial control system (ICS) equipment, specifically impacting critical infrastructure sectors globally. Defenders should be aware of these potential attack vectors that could lead to unauthorized access and control of devices, and monitor for any exploitation attempts.