CVE-2024-39949
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.
Affected (56)
Products: Dahuasecurity: Nvr4104 4ks2/l Firmware, Nvr4108 4ks2/l Firmware, Nvr4116 4ks2/l Firmware, Nvr4104 P 4ks2/l Firmware, Nvr4108 P 4ks2/l Firmware, Nvr4108 8p 4ks2/l Firmware, Nvr4116 8p 4ks2/l Firmware, Nvr4104hs 4ks2/l Firmware, Nvr4108hs 4ks2/l Firmware, Nvr4104hs P 4ks2/l Firmware, Nvr4108hs P 4ks2/l Firmware, Nvr4108hs 8p 4ks2/l Firmware, Nvr4116hs 8p 4ks2/l Firmware, Nvr4204 4ks2/l Firmware, Nvr4208 4ks2/l Firmware, Nvr4216 4ks2/l Firmware, Nvr4204 P 4ks2/l Firmware, Nvr4208 8p 4ks2/l Firmware, Nvr4216 16p 4ks2/l Firmware, Nvr4232 4ks2/l Firmware, Nvr4232 16p 4ks2/l Firmware, Nvr4116hs 4ks2/l Firmware, Nvr4416 4ks2/i Firmware, Nvr4416 16p 4ks2/i Firmware, Nvr4432 16p 4ks2/i Firmware, Nvr4816 4ks2/i Firmware, Nvr4816 16p 4ks2/i Firmware, Nvr4832 4ks2/i Firmware, Nvr4832 16p 4ks2/i Firmware, Nvr4432 4ks2/i Firmware, Nvr4232 4ks3 Firmware, Nvr4232 16p 4ks3 Firmware, Nvr4216 4ks3 Firmware, Nvr4216 16p 4ks3 Firmware, Nvr4208 8p 4ks3 Firmware, Nvr4208 4ks3 Firmware, Nvr4204 P 4ks3 Firmware, Nvr4204 4ks3 Firmware, Nvr4116hs 8p 4ks3 Firmware, Nvr4116hs 4ks3 Firmware, Nvr4108hs P 4ks3 Firmware, Nvr4108hs 8p 4ks3 Firmware, Nvr4108hs 4ks3 Firmware, Nvr4104hs P 4ks3 Firmware, Nvr4104hs 4ks3 Firmware, Nvr4116 8p 4ks3 Firmware, Nvr4116 4ks3 Firmware, Nvr4108 P 4ks3 Firmware, Nvr4104 4ks3 Firmware, Nvr4108 8p 4ks3 Firmware, Nvr4108 4ks3 Firmware, Nvr4104 P 4ks3 Firmware, Nvr4104hs P 4ks3(960g) Firmware, Nvr4104hs 4ks3(960g) Firmware, Nvr4108hs 4ks3(960g) Firmware, Nvr4104 P 4ks3(960g) Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104 4ks2/l | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 4ks2/l | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116 4ks2/l | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104 P 4ks2/l | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 P 4ks2/l | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 8p 4ks2/l | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116 8p 4ks2/l | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs 4ks2/l | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs 4ks2/l | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs P 4ks2/l | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs P 4ks2/l | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs 8p 4ks2/l | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116hs 8p 4ks2/l | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4204 4ks2/l | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4208 4ks2/l | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4216 4ks2/l | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4204 P 4ks2/l | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4208 8p 4ks2/l | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4216 16p 4ks2/l | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4232 4ks2/l | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4232 16p 4ks2/l | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116hs 4ks2/l | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4416 4ks2/i | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4416 16p 4ks2/i | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4432 16p 4ks2/i | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4816 4ks2/i | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4816 16p 4ks2/i | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4832 4ks2/i | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4832 16p 4ks2/i | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4432 4ks2/i | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4232 4ks3 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4232 16p 4ks3 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4216 4ks3 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4216 16p 4ks3 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4208 8p 4ks3 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4208 4ks3 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4204 P 4ks3 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4204 4ks3 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116hs 8p 4ks3 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116hs 4ks3 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs P 4ks3 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs 8p 4ks3 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs 4ks3 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs P 4ks3 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs 4ks3 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116 8p 4ks3 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116 4ks3 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 P 4ks3 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104 4ks3 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 8p 4ks3 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 4ks3 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104 P 4ks3 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs P 4ks3(960g) | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs 4ks3(960g) | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs 4ks3(960g) | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104 P 4ks3(960g) | All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-617
Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
References (1)
Source: cybersecurity@dahuatech.com
Vendor Advisory
Timeline
No history available yet.