CVE-2022-45425: High severity dahua security dss express vulnerability
Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-45425?
CVE-2022-45425 is a vulnerability found in some Dahua software products where a hard-coded cryptographic key is used, allowing an attacker to obtain the AES crypto key.
Which software products are affected by CVE-2022-45425?
Some of the affected Dahua software products include Dahuasecurity Dss Express (version 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, 8.1.1) and Dahuasecurity Dss Professional (version 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, 8.1.1).
What is the severity level of CVE-2022-45425?
CVE-2022-45425 has a severity level of 7.5 (high).
How can an attacker exploit CVE-2022-45425?
An attacker can exploit CVE-2022-45425 by exploiting the vulnerability in the Dahua software products to obtain the AES crypto key.
Is there a fix available for CVE-2022-45425?
Information on fixes for CVE-2022-45425 can be found on the Dahua Security website using the provided reference link.