CVE Vulnerabilities

CVE-2022-30563

Published: Jun 28, 2022 | Modified: Jul 13, 2022
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in through ONVIF, he can log in to the device by replaying the users login packet.

Affected Software

Name Vendor Start Version End Version
Ipc-hdbw2431e-s-s2_firmware Dahuasecurity * 2022-04 (excluding)

References