CVE Vulnerabilities

CVE-2022-30561

Published: Jun 28, 2022 | Modified: Jul 13, 2022
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in, the attacker could log in to the device by replaying the users login packet.

Affected Software

Name Vendor Start Version End Version
Ipc-hdbw2431e-s-s2_firmware Dahuasecurity * 2022-04 (excluding)

References