CVE-2019-9681: Medium severity dahua ipc-hdw1122 vulnerability
Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-9681?
CVE-2019-9681 is a vulnerability in the firmware packages of Dahua products that allows attackers to obtain unencrypted online upgrade information.
Which products are affected by CVE-2019-9681?
The affected products include IPC-HDW1X2X, IPC-HFW1X2X, IPC-HDW2X2X, IPC-HFW2X2X, IPC-HDW4X2X, IPC-HFW4X2X, IPC-HDBW4X2X, IPC-HDW5X2X, and IPC-HFW5X2X.
How severe is CVE-2019-9681?
CVE-2019-9681 has a severity rating of 5.3, which is considered medium.
How can attackers exploit CVE-2019-9681?
Attackers can exploit CVE-2019-9681 by analyzing vulnerable firmware packages to obtain unencrypted online upgrade information.
Is there a fix for CVE-2019-9681?
To fix CVE-2019-9681, it is recommended to update the firmware of the affected Dahua products to a version released after August 18, 2019.