First published: Wed Sep 18 2019(Updated: )
Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.
Credit: cybersecurity@dahuatech.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dahua IPC-HDW1122 | <2019-08-18 | |
Dahua IPC-HDW1122 | ||
Dahua IPC-HFW1120 | <2019-08-18 | |
Dahua IPC-HFW1120 | ||
Dahua IPC-HDW222 | <2019-08-18 | |
Dahua IPC-HDW222 | ||
Dahua IPC-HFW2X2X Firmware | <2019-08-18 | |
Dahua IPC-HFW2X2X | ||
Dahua IPC-HDW4X2X | <2019-08-18 | |
Dahuasecurity IPC-HDW4X2X Firmware | ||
Dahuasecurity IPC-HFW4X2X | <2019-08-18 | |
Dahua IPC-HFW4X2X | ||
Dahua IPC-HDBW4X2X Firmware | <2019-08-18 | |
Dahua IPC-HDBW4X2X | ||
Dahuasecurity IPC-HDW52XX Firmware | <2019-08-18 | |
Dahuasecurity IPC-HDW52XX Firmware | ||
Dahua IPC-HFW5X2X | <2019-08-18 | |
Dahua IPC-HFW5X2X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9679 is a vulnerability in Dahua's Debug functions that allows low-privileged users to use the Debug function after logging in.
The affected products include IPC-HDW1X2X, IPC-HFW1X2X, IPC-HDW2X2X, IPC-HFW2X2X, IPC-HDW4X2X, IPC-HFW4X2X, IPC-HDBW4X2X, IPC-HDW5X2X, and IPC-HFW5X2X for versions up to and excluding 2019-08-18.
The severity of CVE-2019-9679 is high with a CVSS score of 8.8.
To fix CVE-2019-9679, Dahua recommends updating the affected products to a version after 2019-08-18. Refer to the vendor's website for specific instructions.
You can find more information about CVE-2019-9679 on the Dahua Security website at [insert link to reference page].