CVE-2022-45432: Medium severity dahua security dhi-dss7016d-s2 firmware vulnerability
Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices in range of IPs from remote DSS Server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-45432?
CVE-2022-45432 is a vulnerability in some Dahua software products that allows unauthenticated search for devices.
How does CVE-2022-45432 work?
CVE-2022-45432 allows an attacker to bypass the firewall access control policy and send a specific crafted packet to search for devices within a range of IPs.
Which software products are affected by CVE-2022-45432?
Some versions of Dahua DSS Server, Dhi-dss7016d-s2 Firmware, Dhi-dss7016dr-s2 Firmware, Dhi-dss4004-s2 Firmware, Dss Express, and Dss Professional are affected by CVE-2022-45432.
What is the severity of CVE-2022-45432?
CVE-2022-45432 has a severity rating of 5.3 (Medium).
Where can I find more information about CVE-2022-45432?
You can find more information about CVE-2022-45432 on the official Dahua Security website.