CVE-2024-39950
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization.
Affected (58)
Products: Dahuasecurity: Nvr4104 4ks2/l Firmware, Nvr4108 4ks2/l Firmware, Nvr4116 4ks2/l Firmware, Nvr4104 P 4ks2/l Firmware, Nvr4108 P 4ks2/l Firmware, Nvr4108 8p 4ks2/l Firmware, Nvr4116 8p 4ks2/l Firmware, Nvr4104hs 4ks2/l Firmware, Nvr4108hs 4ks2/l Firmware, Nvr4104hs P 4ks2/l Firmware, Nvr4108hs P 4ks2/l Firmware, Nvr4108hs 8p 4ks2/l Firmware, Nvr4116hs 8p 4ks2/l Firmware, Nvr4204 4ks2/l Firmware, Nvr4208 4ks2/l Firmware, Nvr4216 4ks2/l Firmware, Nvr4204 P 4ks2/l Firmware, Nvr4208 8p 4ks2/l Firmware, Nvr4216 16p 4ks2/l Firmware, Nvr4232 4ks2/l Firmware, Nvr4232 16p 4ks2/l Firmware, Nvr4116hs 4ks2/l Firmware, Nvr4416 4ks2/i Firmware, Nvr4416 16p 4ks2/i Firmware, Nvr4432 16p 4ks2/i Firmware, Nvr4816 4ks2/i Firmware, Nvr4816 16p 4ks2/i Firmware, Nvr4832 4ks2/i Firmware, Nvr4832 16p 4ks2/i Firmware, Nvr4432 4ks2/i Firmware, Nvr4232 4ks3 Firmware, Nvr4232 16p 4ks3 Firmware, Nvr4216 4ks3 Firmware, Nvr4216 16p 4ks3 Firmware, Nvr4208 8p 4ks3 Firmware, Nvr4208 4ks3 Firmware, Nvr4204 P 4ks3 Firmware, Nvr4204 4ks3 Firmware, Nvr4116hs 8p 4ks3 Firmware, Nvr4116hs 4ks3 Firmware, Nvr4108hs P 4ks3 Firmware, Nvr4108hs 8p 4ks3 Firmware, Nvr4108hs 4ks3 Firmware, Nvr4104hs P 4ks3 Firmware, Nvr4104hs 4ks3 Firmware, Nvr4116 8p 4ks3 Firmware, Nvr4116 4ks3 Firmware, Nvr4108 P 4ks3 Firmware, Nvr4104 4ks3 Firmware, Nvr4108 8p 4ks3 Firmware, Nvr4108 4ks3 Firmware, Nvr4104 P 4ks3 Firmware, Nvr4104hs P 4ks3(960g) Firmware, Nvr4104hs 4ks3(960g) Firmware, Nvr4108hs 4ks3(960g) Firmware, Nvr4104 P 4ks3(960g) Firmware, Ipc Hfs8849g Z3 Led Firmware, Ipc Hfs8449g Z7 Led Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104 4ks2/l | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 4ks2/l | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116 4ks2/l | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104 P 4ks2/l | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 P 4ks2/l | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 8p 4ks2/l | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116 8p 4ks2/l | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs 4ks2/l | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs 4ks2/l | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs P 4ks2/l | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs P 4ks2/l | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs 8p 4ks2/l | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116hs 8p 4ks2/l | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4204 4ks2/l | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4208 4ks2/l | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4216 4ks2/l | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4204 P 4ks2/l | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4208 8p 4ks2/l | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4216 16p 4ks2/l | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4232 4ks2/l | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4232 16p 4ks2/l | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.1.r.240515 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116hs 4ks2/l | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4416 4ks2/i | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4416 16p 4ks2/i | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4432 16p 4ks2/i | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4816 4ks2/i | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4816 16p 4ks2/i | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4832 4ks2/i | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4832 16p 4ks2/i | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.001.0000001.6.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4432 4ks2/i | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4232 4ks3 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4232 16p 4ks3 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4216 4ks3 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4216 16p 4ks3 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4208 8p 4ks3 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4208 4ks3 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4204 P 4ks3 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4204 4ks3 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116hs 8p 4ks3 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116hs 4ks3 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs P 4ks3 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs 8p 4ks3 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs 4ks3 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs P 4ks3 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs 4ks3 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116 8p 4ks3 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4116 4ks3 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 P 4ks3 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104 4ks3 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 8p 4ks3 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108 4ks3 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104 P 4ks3 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs P 4ks3(960g) | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104hs 4ks3(960g) | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4108hs 4ks3(960g) | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.003.0000000.0.r.240312 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4104 P 4ks3(960g) | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.140.0000000.30.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hfs8849g Z3 Led | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.140.0000000.30.r.240725 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hfs8449g Z7 Led | All versions |
Related CWEs
CWE-121
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
References (1)
Source: cybersecurity@dahuatech.com
Vendor Advisory
Timeline
No history available yet.