CVE Vulnerabilities

CVE-2022-45432

Published: Dec 27, 2022 | Modified: Aug 08, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices in range of IPs from remote DSS Server.

Affected Software

Name Vendor Start Version End Version
Dhi-dss7016d-s2_firmware Dahuasecurity 1.001.0000001.2 (including) 1.001.0000001.2 (including)
Dhi-dss7016d-s2_firmware Dahuasecurity 8.0.2 (including) 8.0.2 (including)
Dhi-dss7016d-s2_firmware Dahuasecurity 8.0.4 (including) 8.0.4 (including)
Dhi-dss7016d-s2_firmware Dahuasecurity 8.1 (including) 8.1 (including)

References