CVE-2022-45427: Malicious File Upload
Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can upload arbitrary files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-45427?
CVE-2022-45427 is a vulnerability found in some Dahua software products that allows an attacker to upload arbitrary files by sending a specific crafted packet to the vulnerable interface.
Which software products are affected by CVE-2022-45427?
The following Dahua software products are affected by CVE-2022-45427: DSS Express 7.002.1760000.2, DSS Express 8.0.2, DSS Express 8.0.4, DSS Express 8.1, DSS Express 8.1.1, DSS Professional 7.002.1760000.2, DSS Professional 8.0.2, DSS Professional 8.0.4, DSS Professional 8.1, DSS Professional 8.1.1, Dhi-dss7016d-s2 Firmware 1.001.0000001.2, Dhi-dss7016d-s2 Firmware 8.0.2, Dhi-dss7016d-s2 Firmware 8.0.4, Dhi-dss7016d-s2 Firmware 8.1, Dhi-dss7016dr-s2 Firmware 1.001.0000001.2, Dhi-dss7016dr-s2 Firmware 8.0.2, Dhi-dss7016dr-s2 Firmware 8.0.4, Dhi-dss7016dr-s2 Firmware 8.1, Dhi-dss4004-s2 Firmware 1.001.0000001.2, Dhi-dss4004-s2 Firmware 8.0.2, Dhi-dss4004-s2 Firmware 8.0.4, Dhi-dss4004-s2 Firmware 8.1.
How severe is CVE-2022-45427?
CVE-2022-45427 has a severity rating of 7.2 (high).
How can I fix CVE-2022-45427?
To fix CVE-2022-45427, it is recommended to update the affected Dahua software products to the latest version provided by the vendor.
Where can I find more information about CVE-2022-45427?
You can find more information about CVE-2022-45427 on the Dahua Security website: https://www.dahuasecurity.com/support/cybersecurity/details/1137