CVE-2020-9500: Medium severity Dahuasecurity Sd6al Firmware vulnerability
Some products of Dahua have Denial of Service vulnerabilities. After the successful login of the legal account, the attacker sends a specific log query command, which may cause the device to go down.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9500?
CVE-2020-9500 is a vulnerability that affects some products of Dahua, allowing an attacker to cause a Denial of Service (DoS) by sending a specific log query command after a successful login.
Which products of Dahua are affected by CVE-2020-9500?
The following Dahua products are affected by CVE-2020-9500: Dahuasecurity Sd6al Firmware (up to version 2019-12), Dahuasecurity Sd5a Firmware (up to version 2019-12), Dahuasecurity Sd1a Firmware (up to version 2019-12), Dahuasecurity Ptz1a Firmware (up to version 2019-12), Dahuasecurity Sd50 Firmware (up to version 2019-12), Dahuasecurity Sd52c Firmware (up to version 2019-12), Dahuasecurity Ipc-hx5842h Firmware (up to version 2019-12), Dahuasecurity Ipc-hx7842h Firmware (up to version 2019-12), Dahuasecurity Ipc-hx2xxx Firmware (up to version 2019-12), Dahuasecurity Ipc-hxxx5x4x Firmware (up to version 2019-12), Dahuasecurity N42b1p Firmware (up to version 2019-12), Dahuasecurity N42b2p Firmware (up to version 2019-12), Dahuasecurity N42b3p Firmware (up to version 2019-12), Dahuasecurity N52a4p Firmware (up to version 2019-12), Dahuasecurity N54a4p Firmware (up to version 2019-12), Dahuasecurity N52b2p Firmware (up to version 2019-12), Dahuasecurity N52b5p Firmware (up to version 2019-12), and Dahuasecurity N52b3p Firmware (up to version 2019-12).
What is the severity of CVE-2020-9500?
The severity of CVE-2020-9500 is medium with a CVSS score of 4.9.
How does CVE-2020-9500 work?
After a successful login with a legal account, an attacker can send a specific log query command to the vulnerable Dahua products, causing a Denial of Service (DoS) and potentially making the device go down.
Is there a fix for CVE-2020-9500?
Currently, there is no known fix or patch for CVE-2020-9500. It is recommended to follow the mitigation steps provided by the vendor and keep the affected products up to date.