CVE Vulnerabilities

CVE-2022-45434

Published: Dec 27, 2022 | Modified: Aug 08, 2023
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.

Affected Software

Name Vendor Start Version End Version
Dhi-dss7016d-s2_firmware Dahuasecurity 1.001.0000001.2 (including) 1.001.0000001.2 (including)
Dhi-dss7016d-s2_firmware Dahuasecurity 8.0.2 (including) 8.0.2 (including)
Dhi-dss7016d-s2_firmware Dahuasecurity 8.0.4 (including) 8.0.4 (including)
Dhi-dss7016d-s2_firmware Dahuasecurity 8.1 (including) 8.1 (including)

References