Lucene search

K

Dahua Security Vulnerabilities

cve
cve

CVE-2023-3121

A vulnerability has been found in Dahua Smart Parking Management up to 20230528 and classified as problematic. This vulnerability affects unknown code of the file /ipms/imageConvert/image. The manipulation of the argument fileUrl leads to server-side request forgery. The exploit has been disclosed....

4.6CVSS

4.9AI Score

0.001EPSS

2023-06-06 11:15 AM
29
cve
cve

CVE-2023-3836

A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can be initiated...

9.8CVSS

9.5AI Score

0.029EPSS

2023-07-22 06:15 PM
29
cve
cve

CVE-2020-9499

Some Dahua products have buffer overflow vulnerabilities. After the successful login of the legal account, the attacker sends a specific DDNS test command, which may cause the device to go...

7.2CVSS

7.1AI Score

0.001EPSS

2020-04-09 02:15 PM
43
2
cve
cve

CVE-2020-9500

Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the attacker sends a specific log query command, which may cause the device to go...

4.9CVSS

5.1AI Score

0.001EPSS

2020-04-09 02:15 PM
47
2
cve
cve

CVE-2019-9679

Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time....

8.8CVSS

8.6AI Score

0.001EPSS

2019-09-18 07:15 PM
29
cve
cve

CVE-2019-9680

Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of the device by constructing malicious data packets. Affected products include:...

5.3CVSS

5.2AI Score

0.001EPSS

2019-09-18 07:15 PM
36
cve
cve

CVE-2019-9678

Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crashed by constructing a malicious packet. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for....

7.5CVSS

7.4AI Score

0.001EPSS

2019-09-18 07:15 PM
31
cve
cve

CVE-2019-9677

The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X.....

9.8CVSS

9.6AI Score

0.003EPSS

2019-09-18 07:15 PM
43
cve
cve

CVE-2019-9681

Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include:...

5.3CVSS

5.2AI Score

0.001EPSS

2019-09-17 05:15 PM
38
cve
cve

CVE-2019-3948

The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and....

7.5CVSS

7.6AI Score

0.074EPSS

2019-07-29 10:15 PM
58
cve
cve

CVE-2017-3223

Dahua IP camera products using firmware versions prior to V2.400.0000.14.R.20170713 include a version of the Sonia web interface that may be vulnerable to a stack buffer overflow. Dahua IP camera products include an application known as Sonia (/usr/bin/sonia) that provides the web interface and...

9.8CVSS

9.8AI Score

0.012EPSS

2018-07-24 03:29 PM
55
cve
cve

CVE-2017-9317

Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the...

8.8CVSS

8.7AI Score

0.001EPSS

2018-05-23 03:29 PM
41
cve
cve

CVE-2017-9315

Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to reset the admin password. The algorithm used in this mechanism is potentially at risk of being compromised and subsequently utilized by...

9.8CVSS

9.3AI Score

0.006EPSS

2017-11-28 07:29 PM
33
cve
cve

CVE-2017-9316

Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerability was caused by internal Debug function. This particular function was used for problem analysis and performance tuning during product development phase. It allowed the device.....

6.5CVSS

7.1AI Score

0.003EPSS

2017-11-27 05:29 PM
20
cve
cve

CVE-2017-9314

Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json...

8.8CVSS

8.7AI Score

0.001EPSS

2017-11-13 04:29 PM
23