CVE Vulnerabilities

CVE-2022-30561

Published: Jun 28, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in, the attacker could log in to the device by replaying the users login packet.

Affected Software

Name Vendor Start Version End Version
Ipc-hdbw2431e-s-s2_firmware Dahuasecurity * 2022-04 (excluding)

References