CVE-2019-9677: Buffer Overflow
The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-9677?
CVE-2019-9677 is a vulnerability in the CGI interface of some Dahua products that allows an attacker to cause a buffer overflow by constructing malicious packets.
Which Dahua products are affected by CVE-2019-9677?
The affected products include IPC-HDW1X2X, IPC-HFW1X2X, IPC-HDW2X2X, IPC-HFW2X2X, IPC-HDW4X2X, IPC-HFW4X2X, IPC-HDBW4X2X, IPC-HDW5X2X, and IPC-HFW5X2X.
What is the severity of CVE-2019-9677?
CVE-2019-9677 has a severity rating of 9.8, which is classified as critical.
How can an attacker exploit CVE-2019-9677?
An attacker can exploit CVE-2019-9677 by constructing malicious packets that can cause a buffer overflow in the affected Dahua products.
Is there a fix for CVE-2019-9677?
Yes, Dahua has released firmware updates to address the vulnerability. It is recommended to update to the latest firmware version to mitigate the risk.