CVE-2022-45426: Medium severity dahua security dss express vulnerability
Some Dahua software products have a vulnerability of unrestricted download of file. After obtaining the permissions of ordinary users, by sending a specific crafted packet to the vulnerable interface, an attacker can download arbitrary files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-45426.
What is the severity of CVE-2022-45426?
The severity of CVE-2022-45426 is medium.
Which Dahua software products are affected by CVE-2022-45426?
Dahuasecurity Dss Express versions 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, and 8.1.1, as well as Dahuasecurity Dss Professional versions 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, and 8.1.1, and Dahuasecurity Dhi-dss7016d-s2 Firmware versions 1.001.0000001.2, 8.0.2, 8.0.4, and 8.1 are affected.
How can an attacker exploit CVE-2022-45426?
An attacker can exploit CVE-2022-45426 by sending a specific crafted packet to the vulnerable interface, allowing them to download arbitrary files.
Where can I find more information about CVE-2022-45426?
More information about CVE-2022-45426 can be found at this [link](https://www.dahuasecurity.com/support/cybersecurity/details/1137).