CVE-2019-9682
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD
Description
Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compatible with the normal login of early devices, some devices retain the weak security login mode that users can control. If the user uses a weak security login method, an attacker can monitor the device network to intercept network packets to attack the device. So it is recommended that the user disable this login method.
Affected (20)
Products: Dahuasecurity: Sd6al Firmware, Sd5a Firmware, Sd1a Firmware, Ptz1a Firmware, Sd50 Firmware, Sd52c Firmware, Ipc Hx5842h Firmware, Ipc Hx7842h Firmware, Ipc Hx2xxx Firmware, Ipc Hxxx5x4x Firmware, N42b1p Firmware, N42b2p Firmware, N42b3p Firmware, N52a4p Firmware, N54a4p Firmware, N52b2p Firmware, N52b5p Firmware, N52b3p Firmware, N54b2p Firmware, Ipc Hdbw1320e W Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Sd6al | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Sd5a | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Sd1a | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ptz1a | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Sd50 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Sd52c | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hx5842h | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hx7842h | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hx2xxx | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hxxx5x4x | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity N42b1p | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity N42b2p | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity N42b3p | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity N52a4p | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity N54a4p | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity N52b2p | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity N52b5p | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity N52b3p | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity N54b2p | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2019-12 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hdbw1320e W | All versions |
References (2)
Source: cybersecurity@dahuatech.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.