Lucene search

K
cve[email protected]CVE-2020-9499
HistoryApr 09, 2020 - 2:15 p.m.

CVE-2020-9499

2020-04-0914:15:13
CWE-120
web.nvd.nist.gov
43
2
cve-2020-9499
dahua
buffer overflow
vulnerability
ddns
device downtime
security
nvd

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.6%

Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go down.

Affected configurations

NVD
Node
dahuasecuritysd6alMatch-
AND
dahuasecuritysd6al_firmwareRange<2019-12
Node
dahuasecuritysd5aMatch-
AND
dahuasecuritysd5a_firmwareRange<2019-12
Node
dahuasecuritysd1aMatch-
AND
dahuasecuritysd1a_firmwareRange<2019-12
Node
dahuasecurityptz1aMatch-
AND
dahuasecurityptz1a_firmwareRange<2019-12
Node
dahuasecuritysd50Match-
AND
dahuasecuritysd50_firmwareRange<2019-12
Node
dahuasecuritysd52cMatch-
AND
dahuasecuritysd52c_firmwareRange<2019-12
Node
dahuasecurityipc-hx5842hMatch-
AND
dahuasecurityipc-hx5842h_firmwareRange<2019-12
Node
dahuasecurityipc-hx7842hMatch-
AND
dahuasecurityipc-hx7842h_firmwareRange<2019-12
Node
dahuasecurityipc-hx2xxx_firmwareRange<2019-12
AND
dahuasecurityipc-hx2xxxMatch-
Node
dahuasecurityipc-hxxx5x4x_firmwareRange<2019-12
AND
dahuasecurityipc-hxxx5x4xMatch-
Node
dahuasecurityn42b1p_firmwareRange<2019-12
AND
dahuasecurityn42b1pMatch-
Node
dahuasecurityn42b2p_firmwareRange<2019-12
AND
dahuasecurityn42b2pMatch-
Node
dahuasecurityn42b3p_firmwareRange<2019-12
AND
dahuasecurityn42b3pMatch-
Node
dahuasecurityn52a4p_firmwareRange<2019-12
AND
dahuasecurityn52a4pMatch-
Node
dahuasecurityn54a4p_firmwareRange<2019-12
AND
dahuan54a4pMatch-
Node
dahuasecurityn52b2p_firmwareRange<2019-12
AND
dahuasecurityn52b2pMatch-
Node
dahuasecurityn52b5p_firmwareRange<2019-12
AND
dahuasecurityn52b5pMatch-
Node
dahuasecurityn52b3p_firmwareRange<2019-12
AND
dahuasecurityn52b3pMatch-
Node
dahuasecurityn54b2p_firmwareRange<2019-12
AND
dahuasecurityn54b2pMatch-

CNA Affected

[
  {
    "product": "IPC-HX2XXX Series,IPC-HXXX5X4X Series,IPC-HX5842H,IPC-HX7842H,NVR 5x Series,NVR 4x Series,SD6AL Series,SD5A Series,SD1A Series,PTZ1A Series,SD50/52C Series",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions which Build time before December,2019"
      }
    ]
  }
]

Social References

More

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.6%

Related for CVE-2020-9499