9.8

CVE-2020-9502

Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DahuasecuritySd6al Firmware Version < 2019-12
   DahuasecuritySd6al Version-
DahuasecuritySd5a Firmware Version < 2019-12
   DahuasecuritySd5a Version-
DahuasecuritySd1a Firmware Version < 2019-12
   DahuasecuritySd1a Version-
DahuasecurityPtz1a Firmware Version < 2019-12
   DahuasecurityPtz1a Version-
DahuasecuritySd50 Firmware Version < 2019-12
   DahuasecuritySd50 Version-
DahuasecuritySd52c Firmware Version < 2019-12
   DahuasecuritySd52c Version-
DahuasecurityIpc-hx5842h Firmware Version < 2019-12
   DahuasecurityIpc-hx5842h Version-
DahuasecurityIpc-hx7842h Firmware Version < 2019-12
   DahuasecurityIpc-hx7842h Version-
DahuasecurityIpc-hx2xxx Firmware Version < 2019-12
   DahuasecurityIpc-hx2xxx Version-
DahuasecurityIpc-hxxx5x4x Firmware Version < 2019-12
   DahuasecurityIpc-hxxx5x4x Version-
DahuasecurityN42b1p Firmware Version < 2019-12
   DahuasecurityN42b1p Version-
DahuasecurityN42b2p Firmware Version < 2019-12
   DahuasecurityN42b2p Version-
DahuasecurityN42b3p Firmware Version < 2019-12
   DahuasecurityN42b3p Version-
DahuasecurityN52a4p Firmware Version < 2019-12
   DahuasecurityN52a4p Version-
DahuasecurityN54a4p Firmware Version < 2019-12
   DahuasecurityN54a4p Version-
DahuasecurityN52b2p Firmware Version < 2019-12
   DahuasecurityN52b2p Version-
DahuasecurityN52b5p Firmware Version < 2019-12
   DahuasecurityN52b5p Version-
DahuasecurityN52b3p Firmware Version < 2019-12
   DahuasecurityN52b3p Version-
DahuasecurityN54b2p Firmware Version < 2019-12
   DahuasecurityN54b2p Version-
DahuasecurityIpc-hdbw1320e-w Firmware Version < 2019-12
   DahuasecurityIpc-hdbw1320e-w Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.687
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-330 Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.