First published: Wed Sep 18 2019(Updated: )
The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.
Credit: cybersecurity@dahuatech.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dahuasecurity Ipc-hdw1x2x Firmware | <2019-08-18 | |
Dahuasecurity Ipc-hdw1x2x | ||
Dahuasecurity Ipc-hfw1x2x Firmware | <2019-08-18 | |
Dahuasecurity Ipc-hfw1x2x | ||
Dahuasecurity Ipc-hdw2x2x Firmware | <2019-08-18 | |
Dahuasecurity Ipc-hdw2x2x | ||
Dahuasecurity Ipc-hfw2x2x Firmware | <2019-08-18 | |
Dahuasecurity Ipc-hfw2x2x | ||
Dahuasecurity Ipc-hdw4x2x Firmware | <2019-08-18 | |
Dahuasecurity Ipc-hdw4x2x | ||
Dahuasecurity Ipc-hfw4x2x Firmware | <2019-08-18 | |
Dahuasecurity Ipc-hfw4x2x | ||
Dahuasecurity Ipc-hdbw4x2x Firmware | <2019-08-18 | |
Dahuasecurity Ipc-hdbw4x2x | ||
Dahuasecurity Ipc-hdw5x2x Firmware | <2019-08-18 | |
Dahuasecurity Ipc-hdw5x2x | ||
Dahuasecurity Ipc-hfw5x2x Firmware | <2019-08-18 | |
Dahuasecurity Ipc-hfw5x2x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9677 is a vulnerability in the CGI interface of some Dahua products that allows an attacker to cause a buffer overflow by constructing malicious packets.
The affected products include IPC-HDW1X2X, IPC-HFW1X2X, IPC-HDW2X2X, IPC-HFW2X2X, IPC-HDW4X2X, IPC-HFW4X2X, IPC-HDBW4X2X, IPC-HDW5X2X, and IPC-HFW5X2X.
CVE-2019-9677 has a severity rating of 9.8, which is classified as critical.
An attacker can exploit CVE-2019-9677 by constructing malicious packets that can cause a buffer overflow in the affected Dahua products.
Yes, Dahua has released firmware updates to address the vulnerability. It is recommended to update to the latest firmware version to mitigate the risk.