7.5
CVE-2024-39948
- EPSS 0.35%
- Veröffentlicht 31.07.2024 04:15:05
- Zuletzt bearbeitet 30.09.2025 11:37:36
- Quelle cybersecurity@dahuatech.com
- CVE-Watchlists
- Unerledigt
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dahuasecurity ≫ Nvr4232-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4232-16p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4216-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4216-16p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4208-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4208-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4204-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4204-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4116hs-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4116hs-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108hs-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108hs-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108hs-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4104hs-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4104hs-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4116-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4116-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4104-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4104-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.57 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| cybersecurity@dahuatech.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.