7.5
CVE-2024-39949
- EPSS 0.17%
- Veröffentlicht 31.07.2024 04:15:05
- Zuletzt bearbeitet 30.09.2025 11:37:36
- Quelle cybersecurity@dahuatech.com
- CVE-Watchlists
- Unerledigt
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dahuasecurity ≫ Nvr4232-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4232-16p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4216-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4216-16p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4208-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4208-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4204-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4204-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4116hs-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4116hs-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108hs-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108hs-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108hs-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4104hs-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4104hs-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4116-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4116-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4104-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108-8p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4108-4ks3 Firmware Version < 4.003.0000000.0.r.240312
Dahuasecurity ≫ Nvr4104-p-4ks3 Firmware Version < 4.003.0000000.0.r.240312
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.377 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| cybersecurity@dahuatech.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-617 Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.