CVE-2022-45430: Low severity dahua security dss express vulnerability
Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could enable or disable the SSHD service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-45430?
CVE-2022-45430 is a vulnerability in some Dahua software products that allows an attacker to enable or disable the SSHD service without authentication.
Which software products are affected by CVE-2022-45430?
The Dahua DSS Express versions 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, and 8.1.1, as well as the Dahua DSS Professional versions 7.002.1760000.2, 8.0.2, 8.0.4, 8.1, and 8.1.1 are affected by CVE-2022-45430.
What is the severity of CVE-2022-45430?
CVE-2022-45430 has a severity rating of low with a CVSS score of 3.7.
How can an attacker exploit CVE-2022-45430?
An attacker can exploit CVE-2022-45430 by bypassing the firewall access control policy and sending a specific crafted packet to the vulnerable interface.
Where can I find more information on CVE-2022-45430?
You can find more information on CVE-2022-45430 on the Dahua Security support website at https://www.dahuasecurity.com/support/cybersecurity/details/1137.