CVE-2024-51348

8.8

BS Producten · Petcam

A stack-based buffer overflow in the Petcam P2P API service allows unauthenticated, network-adjacent attackers to achieve remote code execution via crafted HTTP requests.

Executive summary

A critical stack-based buffer overflow vulnerability in BS Producten Petcam firmware 33.1.0.0818 enables unauthenticated remote code execution.

Vulnerability

The vulnerability exists in the P2P API service, where a lack of proper input validation allows an unauthenticated attacker within network range to overwrite the instruction pointer. This flaw permits the execution of arbitrary code through a specially crafted HTTP request.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain full control over the affected device, potentially leading to unauthorized surveillance or the compromise of the local network. Given the CVSS score of 8.8, this represents a high-severity risk that could result in significant privacy breaches and loss of device integrity.

Remediation

Immediate Action: As no specific patch is currently available, immediately isolate affected Petcam devices from the public internet and restrict access to authorized network segments only.

Proactive Monitoring: Review device access logs for unusual HTTP requests targeting the P2P API service and monitor network traffic for unexpected outbound connections from the camera.

Compensating Controls: Deploy a network-based firewall or intrusion detection system to block unauthorized traffic directed at the camera's management ports, effectively mitigating the attack vector.

Exploitation status

Public Exploit Available: Yes, a published PoC exists, attributed to the security researcher's technical write-up provided in the referenced GitHub repository.

Analyst recommendation

The severity of this vulnerability, combined with the presence of a public proof-of-concept, necessitates immediate action to restrict network exposure. Administrators should prioritize isolating these devices from external networks until a vendor-supplied firmware update is released and verified.

Sources