CVE-2022-45423: High severity dahua security dss express vulnerability
Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface (the credentials cannot be directly exploited).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Dahua software vulnerability?
The vulnerability ID for this Dahua software vulnerability is CVE-2022-45423.
What is the severity rating of CVE-2022-45423?
CVE-2022-45423 has a severity rating of 7.5 (High).
Which Dahua software products are affected by this vulnerability?
The following Dahua software products are affected by this vulnerability: Dahuasecurity Dss Express (version 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, 8.1.1), Dahuasecurity Dss Professional (version 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, 8.1.1), Dahuasecurity Dhi-dss7016d-s2 Firmware (version 1.001.0000001.2, 8.0.2, 8.0.4, 8.1), Dahuasecurity Dhi-dss7016dr-s2 Firmware (version 1.001.0000001.2, 8.0.2, 8.0.4, 8.1), Dahuasecurity Dhi-dss4004-s2 Firmware (version 1.001.0000001.2, 8.0.2, 8.0.4, 8.1).
How can an attacker exploit this vulnerability?
An attacker can obtain encrypted MQTT credentials by sending a specific crafted packet to the vulnerable interface, although the credentials cannot be directly exploited.
Where can I find more information about CVE-2022-45423?
You can find more information about CVE-2022-45423 at the following reference link: [Dahua Security Cybersecurity Advisory](https://www.dahuasecurity.com/support/cybersecurity/details/1137).