CVE-2022-45424: Medium severity dahua security dss express vulnerability
Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending a specific crafted packet to the vulnerable interface.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45424?
The severity of CVE-2022-45424 is medium with a CVSS score of 5.3.
Which Dahua software products are affected by CVE-2022-45424?
Dahuasecurity Dss Express versions 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, and 8.1.1, as well as Dahuasecurity Dss Professional versions 7.002.1760000.2, 8.0.2, 8.0.4, and 8.1, and Dahuasecurity Dhi-dss7016d-s2 Firmware versions 1.001.0000001.2, 8.0.2, 8.0.4, and 8.1 are affected.
How can an attacker exploit CVE-2022-45424?
An attacker can exploit CVE-2022-45424 by sending a specific crafted packet to the vulnerable interface to obtain the AES crypto key.
Is there a fix for CVE-2022-45424?
Yes, it is recommended to update to the latest version of the affected software products, as provided by Dahua Security.
Where can I find more information about CVE-2022-45424?
You can find more information about CVE-2022-45424 on the Dahua Security website at the following link: [https://www.dahuasecurity.com/support/cybersecurity/details/1137](https://www.dahuasecurity.com/support/cybersecurity/details/1137)