Dahuasecurity

Ipc-hfw4x2x Firmware

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.54%
  • Veröffentlicht 18.09.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:52:05

Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crashed by constructing a malicious packet. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-...

  • EPSS 0.33%
  • Veröffentlicht 18.09.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:52:06

Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-H...

  • EPSS 0.37%
  • Veröffentlicht 18.09.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:52:06

Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of the device by constructing malicious data packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC...

  • EPSS 0.86%
  • Veröffentlicht 18.09.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 04:52:05

The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,I...

  • EPSS 0.17%
  • Veröffentlicht 17.09.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:52:06

Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2...