CVE-2022-45428: Low severity dahua security dss express vulnerability
Some Dahua software products have a vulnerability of sensitive information leakage. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can obtain the debugging information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this Dahua software vulnerability?
This vulnerability is identified by the CVE-2022-45428 ID.
What is the severity level of CVE-2022-45428?
The severity level of CVE-2022-45428 is low, with a severity value of 2.7.
Which Dahua software products are affected by CVE-2022-45428?
Dahuasecurity Dss Express (versions 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, 8.1.1) and Dahuasecurity Dss Professional (versions 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, 8.1.1) are affected by CVE-2022-45428.
What can an attacker do with CVE-2022-45428?
An attacker with administrator permissions can obtain sensitive information by sending a crafted packet to the vulnerable interface.
Is there a fix available for CVE-2022-45428?
For information on available fixes for CVE-2022-45428, please refer to the official Dahua Security website.