First published: Tue Dec 27 2022(Updated: )
Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can upload arbitrary files.
Credit: cybersecurity@dahuatech.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dahuasecurity Dss Express | =7.002.1760000.2 | |
Dahuasecurity Dss Express | =8.0.2 | |
Dahuasecurity Dss Express | =8.0.4 | |
Dahuasecurity Dss Express | =8.1 | |
Dahuasecurity Dss Express | =8.1.1 | |
Dahuasecurity Dss Professional | =7.002.1760000.2 | |
Dahuasecurity Dss Professional | =8.0.2 | |
Dahuasecurity Dss Professional | =8.0.4 | |
Dahuasecurity Dss Professional | =8.1 | |
Dahuasecurity Dss Professional | =8.1.1 | |
Dahuasecurity Dhi-dss7016d-s2 Firmware | =1.001.0000001.2 | |
Dahuasecurity Dhi-dss7016d-s2 Firmware | =8.0.2 | |
Dahuasecurity Dhi-dss7016d-s2 Firmware | =8.0.4 | |
Dahuasecurity Dhi-dss7016d-s2 Firmware | =8.1 | |
Dahuasecurity Dhi-dss7016d-s2 | ||
Dahuasecurity Dhi-dss7016dr-s2 Firmware | =1.001.0000001.2 | |
Dahuasecurity Dhi-dss7016dr-s2 Firmware | =8.0.2 | |
Dahuasecurity Dhi-dss7016dr-s2 Firmware | =8.0.4 | |
Dahuasecurity Dhi-dss7016dr-s2 Firmware | =8.1 | |
Dahuasecurity Dhi-dss7016dr-s2 | ||
Dahuasecurity Dhi-dss4004-s2 Firmware | =1.001.0000001.2 | |
Dahuasecurity Dhi-dss4004-s2 Firmware | =8.0.2 | |
Dahuasecurity Dhi-dss4004-s2 Firmware | =8.0.4 | |
Dahuasecurity Dhi-dss4004-s2 Firmware | =8.1 | |
Dahuasecurity Dhi-dss4004-s2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45427 is a vulnerability found in some Dahua software products that allows an attacker to upload arbitrary files by sending a specific crafted packet to the vulnerable interface.
The following Dahua software products are affected by CVE-2022-45427: DSS Express 7.002.1760000.2, DSS Express 8.0.2, DSS Express 8.0.4, DSS Express 8.1, DSS Express 8.1.1, DSS Professional 7.002.1760000.2, DSS Professional 8.0.2, DSS Professional 8.0.4, DSS Professional 8.1, DSS Professional 8.1.1, Dhi-dss7016d-s2 Firmware 1.001.0000001.2, Dhi-dss7016d-s2 Firmware 8.0.2, Dhi-dss7016d-s2 Firmware 8.0.4, Dhi-dss7016d-s2 Firmware 8.1, Dhi-dss7016dr-s2 Firmware 1.001.0000001.2, Dhi-dss7016dr-s2 Firmware 8.0.2, Dhi-dss7016dr-s2 Firmware 8.0.4, Dhi-dss7016dr-s2 Firmware 8.1, Dhi-dss4004-s2 Firmware 1.001.0000001.2, Dhi-dss4004-s2 Firmware 8.0.2, Dhi-dss4004-s2 Firmware 8.0.4, Dhi-dss4004-s2 Firmware 8.1.
CVE-2022-45427 has a severity rating of 7.2 (high).
To fix CVE-2022-45427, it is recommended to update the affected Dahua software products to the latest version provided by the vendor.
You can find more information about CVE-2022-45427 on the Dahua Security website: https://www.dahuasecurity.com/support/cybersecurity/details/1137