Lucene search

K
cveDahuaCVE-2022-45429
HistoryDec 27, 2022 - 6:15 p.m.

CVE-2022-45429

2022-12-2718:15:10
CWE-918
dahua
web.nvd.nist.gov
39
dahua
software
vulnerability
ssrf
url
nvd
cve-2022-45429

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

51.6%

Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal resources by concatenating links (URL) that conform to specific rules.

Affected configurations

Nvd
Node
dahuasecuritydss_expressMatch7.002.1760000.2
OR
dahuasecuritydss_expressMatch8.0.2
OR
dahuasecuritydss_expressMatch8.0.4
OR
dahuasecuritydss_expressMatch8.1
OR
dahuasecuritydss_expressMatch8.1.1
OR
dahuasecuritydss_professionalMatch7.002.1760000.2
OR
dahuasecuritydss_professionalMatch8.0.2
OR
dahuasecuritydss_professionalMatch8.0.4
OR
dahuasecuritydss_professionalMatch8.1
OR
dahuasecuritydss_professionalMatch8.1.1
Node
dahuasecuritydhi-dss7016d-s2_firmwareMatch1.001.0000001.2
OR
dahuasecuritydhi-dss7016d-s2_firmwareMatch8.0.2
OR
dahuasecuritydhi-dss7016d-s2_firmwareMatch8.0.4
OR
dahuasecuritydhi-dss7016d-s2_firmwareMatch8.1
AND
dahuasecuritydhi-dss7016d-s2Match-
Node
dahuasecuritydhi-dss7016dr-s2_firmwareMatch1.001.0000001.2
OR
dahuasecuritydhi-dss7016dr-s2_firmwareMatch8.0.2
OR
dahuasecuritydhi-dss7016dr-s2_firmwareMatch8.0.4
OR
dahuasecuritydhi-dss7016dr-s2_firmwareMatch8.1
AND
dahuasecuritydhi-dss7016dr-s2Match-
Node
dahuasecuritydhi-dss4004-s2_firmwareMatch1.001.0000001.2
OR
dahuasecuritydhi-dss4004-s2_firmwareMatch8.0.2
OR
dahuasecuritydhi-dss4004-s2_firmwareMatch8.0.4
OR
dahuasecuritydhi-dss4004-s2_firmwareMatch8.1
AND
dahuasecuritydhi-dss4004-s2Match-
VendorProductVersionCPE
dahuasecuritydss_express7.002.1760000.2cpe:2.3:a:dahuasecurity:dss_express:7.002.1760000.2:*:*:*:*:*:*:*
dahuasecuritydss_express8.0.2cpe:2.3:a:dahuasecurity:dss_express:8.0.2:*:*:*:*:*:*:*
dahuasecuritydss_express8.0.4cpe:2.3:a:dahuasecurity:dss_express:8.0.4:*:*:*:*:*:*:*
dahuasecuritydss_express8.1cpe:2.3:a:dahuasecurity:dss_express:8.1:*:*:*:*:*:*:*
dahuasecuritydss_express8.1.1cpe:2.3:a:dahuasecurity:dss_express:8.1.1:*:*:*:*:*:*:*
dahuasecuritydss_professional7.002.1760000.2cpe:2.3:a:dahuasecurity:dss_professional:7.002.1760000.2:*:*:*:*:*:*:*
dahuasecuritydss_professional8.0.2cpe:2.3:a:dahuasecurity:dss_professional:8.0.2:*:*:*:*:*:*:*
dahuasecuritydss_professional8.0.4cpe:2.3:a:dahuasecurity:dss_professional:8.0.4:*:*:*:*:*:*:*
dahuasecuritydss_professional8.1cpe:2.3:a:dahuasecurity:dss_professional:8.1:*:*:*:*:*:*:*
dahuasecuritydss_professional8.1.1cpe:2.3:a:dahuasecurity:dss_professional:8.1.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 251

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "DSS Professional, DSS Express, DHI-DSS7016D-S2/DHI-DSS7016DR-S2, DHI-DSS4004-S2",
    "versions": [
      {
        "version": "V8.0.2, V8.0.4, V8.1",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

51.6%

Related for CVE-2022-45429