4.9

CVE-2024-39945

A vulnerability has been found in Dahua products.  After
obtaining the administrator's username and password, the attacker can send a
carefully crafted data packet to the interface with vulnerabilities, causing
the device to crash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DahuasecurityNvr4232-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4232-4ks3 Version-
DahuasecurityNvr4232-16p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4232-16p-4ks3 Version-
DahuasecurityNvr4216-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4216-4ks3 Version-
DahuasecurityNvr4216-16p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4216-16p-4ks3 Version-
DahuasecurityNvr4208-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4208-8p-4ks3 Version-
DahuasecurityNvr4208-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4208-4ks3 Version-
DahuasecurityNvr4204-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4204-p-4ks3 Version-
DahuasecurityNvr4204-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4204-4ks3 Version-
DahuasecurityNvr4116hs-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4116hs-8p-4ks3 Version-
DahuasecurityNvr4116hs-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4116hs-4ks3 Version-
DahuasecurityNvr4108hs-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4108hs-p-4ks3 Version-
DahuasecurityNvr4108hs-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4108hs-8p-4ks3 Version-
DahuasecurityNvr4108hs-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4108hs-4ks3 Version-
DahuasecurityNvr4104hs-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4104hs-p-4ks3 Version-
DahuasecurityNvr4104hs-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4104hs-4ks3 Version-
DahuasecurityNvr4116-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4116-8p-4ks3 Version-
DahuasecurityNvr4116-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4116-4ks3 Version-
DahuasecurityNvr4108-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4108-p-4ks3 Version-
DahuasecurityNvr4104-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4104-4ks3 Version-
DahuasecurityNvr4108-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4108-8p-4ks3 Version-
DahuasecurityNvr4108-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4108-4ks3 Version-
DahuasecurityNvr4104-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
   DahuasecurityNvr4104-p-4ks3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.456
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
cybersecurity@dahuatech.com 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE-703 Improper Check or Handling of Exceptional Conditions

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.