Successful exploitation of the improper input validation control could allow a remote attacker to cause the RTSP service to crash.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Multiple Format String (CVE-2022-38157) | Successful exploitation of the multiple format string vulnerabilities in Moxa’s VPort IP Camera series can crash the RTSP service. |
| 2 | Multiple Buffer Overflows (CVE-2022-31858) | Successful exploitation of the multiple buffer overflow vulnerabilities in Moxa’s VPort IP Camera series can crash the RTSP service. |
| 3 | NULL Pointer Dereference Vulnerability (CVE-2022-38159) | Successful exploitation of the NULL pointer dereference vulnerability in Moxa’s VPort IP Camera series can crash the RTSP service. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/vport-series-improper-input-validation-vulnerability